<html><body><div style="color:#000; background-color:#fff; font-family:arial, helvetica, sans-serif;font-size:12pt"><div><span>I asked the client to test after I made the sign="true" setting but he says he is still not getting a signed authNRequest:</span></div><div><br><span></span></div><div class="MsoNormal" style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; background-color: rgb(255, 255, 255); "><span style="font-size: 11pt; color: rgb(31, 73, 125); ">I still do not see the signature in the AuthNRequest:</span></div><div class="MsoNormal"
 style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; background-color: rgb(255, 255, 255); "><span style="font-size: 11pt; color: rgb(31, 73, 125); ">&nbsp;</span></div><div class="MsoNormal" style="margin: 0px; color: rgb(34, 34, 34); font-family: arial,sans-serif; font-size: 13px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; background-color: rgb(255, 255, 255);"><span style="font-size: 11pt;
 color: rgb(31, 73, 125);">&lt;samlp:AuthnRequest xmlns:samlp="urn:oasis:names:<wbr>tc:SAML:2.0:protocol" AssertionConsumerServiceURL="<a href="https://shib.lynda.com/Shibboleth.sso/SAML2/POST" target="_blank" style="color: rgb(53, 66, 88); ">h<wbr>ttps://shib.lynda.com/<wbr>Shibboleth.sso/SAML2/POST</a>" Destination="<a href="https://alliancetest.qualcomm.com/fed/idp/samlv20" target="_blank" style="color: rgb(53, 66, 88); ">https://<wbr>alliancetest.qualcomm.com/fed/<wbr>idp/samlv20</a>" ID="_<wbr>25673b8d16e076e3dc1caf2815a02a<wbr>3a" IssueInstant="2011-11-03T20:<wbr>02:51Z" ProtocolBinding="urn:oasis:<wbr>names:tc:SAML:2.0:bindings:<wbr>HTTP-POST" Version="2.0"&gt;&lt;saml:Issuer xmlns:saml="urn:oasis:names:<wbr>tc:SAML:2.0:assertion"&gt;<a href="https://shib.lynda.com/shibboleth-sp" target="_blank" style="color: rgb(53, 66, 88); ">https:/<wbr>/shib.lynda.com/shibboleth-sp</a>&lt;<wbr>/saml:Issuer&gt;&lt;samlp:<wbr>NameIDPolicy
 AllowCreate="1"/&gt;&lt;/samlp:<wbr>AuthnRequest&gt;</span></div><div class="MsoNormal" style="margin: 0px; color: rgb(34, 34, 34); font-family: arial,sans-serif; font-size: 13px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; background-color: rgb(255, 255, 255);"><br><span style="font-size: 11pt; color: rgb(31, 73, 125);"></span></div><div class="MsoNormal" style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto;
 -webkit-text-stroke-width: 0px; background-color: rgb(255, 255, 255); "><span style="font-size: 11pt; color: rgb(31, 73, 125); ">Any thoughts?<br></span></div><div><br></div><div style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><div style="font-family: times new roman, new york, times, serif; font-size: 12pt;"><font size="2" face="Arial"><hr size="1"><b><span style="font-weight:bold;">From:</span></b> Mark K. Miller &lt;max@psu.edu&gt;<br><b><span style="font-weight: bold;">To:</span></b> Shib Users &lt;users@shibboleth.net&gt;<br><b><span style="font-weight: bold;">Sent:</span></b> Thursday, November 3, 2011 12:37 PM<br><b><span style="font-weight: bold;">Subject:</span></b> Re: authn request signing<br></font><br>
<br>Mike and I just finished testing again; it works now.&nbsp; Scott was <br>absolutely correct about the metadata.<br><br>Thanks for your help, Scott!<br><br>On Thu, 3 Nov 2011, Mark K. Miller wrote:<br><br>&gt; On Thu, 3 Nov 2011, Cantor, Scott wrote:<br>&gt;<br>&gt;&gt; On 11/3/11 11:26 AM, "Mike Flynn" &lt;<a ymailto="mailto:shibbolethlynda@yahoo.com" href="mailto:shibbolethlynda@yahoo.com">shibbolethlynda@yahoo.com</a>&gt; wrote:<br>&gt;&gt;&gt;<br>&gt;&gt;&gt; And then<br>&gt;&gt;&gt; did a test with Max at PSU.&nbsp; It failed.<br>&gt;&gt;<br>&gt;&gt; If it failed, then I would imagine your metadata must be wrong. The only<br>&gt;&gt; reason it should fail is if your signature wasn't trusted.<br>&gt;<br>&gt; I imagine that you imagine correctly (as always.)<br>&gt;<br>&gt; I feel real silly that I didn't realize this.&nbsp; Especially, given that upon<br>&gt; declaring the test a failure I went right off and updated my metadata<br>&gt; because
 Mike was up to the steps in the key rollover process where he had<br>&gt; added another cert to the metadata.<br>&gt;<br>&gt; In a separate note directly to Mike, I suggested we repeat the test and I<br>&gt; expect it'll work now.<br>&gt;<br>&gt; Thanks, Scott!<br>&gt;<br>&gt;&gt;&gt; Do I need to include the encryption setting and have it set to true along<br>&gt;&gt;&gt; with signing="true"?<br>&gt;&gt;<br>&gt;&gt; There is nothing in the request that's encrypted, the setting won't matter.<br>&gt;&gt;<br>&gt;&gt;&gt; If these values are not present in the ApplicationDefaults, I presume<br>&gt;&gt;&gt; that Shibboleth defaults them both to false - correct?<br>&gt;&gt;<br>&gt;&gt; Yes; you can find that out in the documentation. I documented every<br>&gt;&gt; setting.<br>&gt;&gt;<br>&gt;&gt;&gt; Is this customer wrong when they indicate that authn request signing will<br>&gt;&gt;&gt; have no impact on existing Idps?&nbsp; I assume they are since PSU's
 shib<br>&gt;&gt;&gt; connection attempt failed.&nbsp; Or, would setting both encryption and signing<br>&gt;&gt;&gt; on applicationdefaults have prevented the error?<br>&gt;&gt;<br>&gt;&gt; No, and any time the metadata is wrong, virtually anything can fail.<br>&gt;&gt;<br>&gt;&gt; You can also override the setting for the specific relying party, as<br>&gt;&gt; documented.<br>&gt;&gt;<br>&gt;&gt; -- Scott<br>&gt;&gt;<br>&gt;&gt; --<br>&gt;&gt; To unsubscribe from this list send an email to <a ymailto="mailto:users-unsubscribe@shibboleth.net" href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>&gt; --<br>&gt; To unsubscribe from this list send an email to <a ymailto="mailto:users-unsubscribe@shibboleth.net" href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>&gt;<br>--<br>To unsubscribe from this list send an email to <a ymailto="mailto:users-unsubscribe@shibboleth.net"
 href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br><br><br></div></div></div></body></html>