<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; color: rgb(0, 0, 0); font-family: Calibri, sans-serif; ">
<div>Hello SAML mavens,</div>
<div style="font-size: 16px; "><span style="font-size: 18px; "><br>
</span></div>
<div style="font-size: 16px; ">I have a SAML security question. &nbsp;</div>
<div style="font-size: 16px; "><br>
</div>
<div style="font-size: 16px; ">We're a SP supporting IdP-initiated SSO. &nbsp;We have an IdP who would like to send signed SAML responses but convey the user-identifying data as additional https POST parameters rather than including this information within the signed
 message.</div>
<div style="font-size: 16px; "><br>
</div>
<div style="font-size: 16px; ">The IdP feels this would be secure. &nbsp;To me it seems inherently insecure because the identifying information wouldn't be signed, but I'm hard-pressed to imagine a scenario where an attacker could take advantage of it.</div>
<div style="font-size: 16px; "><br>
</div>
<div style="font-size: 16px; ">Can anyone tell me whether this would be secure, and why? &nbsp;Any informed opinions would be greatly appreciated!</div>
<div style="font-size: 16px; "><br>
</div>
<div style="font-size: 16px; "><span class="Apple-style-span" style="font-size: medium; ">
<div style="font-size: 16px; ">(Apologies if this question isn't appropriate for this forum, in which case I'd appreciate recommendations for where to post it.)</div>
<div><br>
</div>
</span></div>
<div style="font-size: 16px; ">Thanks,</div>
<div style="font-size: 16px; ">Peter</div>
<div style="font-size: 16px; "><br>
</div>
</body>
</html>