<html><head><meta http-equiv="Content-Type" content="text/html charset=us-ascii"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; "><div><span style="font-size: 13px;"><font face="Lucida Sans">I have a vendor that is currently sending unsigned authN requests [having persuaded them to remove an errant X.509 certificate embedded in the request]. My IdP objects that the unsigned request does not meet security requirements (refusing to process it). As this is a service providing electronic signatures for work flow and approval documents, it has seemed to me reasonable and prudent to ask that they digitally sign the authN request to our IdP. </font></span></div><div><span style="font-size: 13px;"><font face="Lucida Sans"><br></font></span></div><div><span style="font-size: 13px;"><font face="Lucida Sans">* Am I off base in asking for signed authN request? Isn't that usual?</font></span></div><div><span style="font-size: 13px;"><font face="Lucida Sans"><br></font></span></div><div><span style="font-size: 13px;"><font face="Lucida Sans">* If they are unable or unwilling [sic!] to sign the SAML authN request, I presume I can configure my IdP to permit unsigned requests from them, but I haven't discovered the documentation for doing so. </font></span></div><div><span style="font-size: 13px;"><font face="Lucida Sans"><br></font></span></div><div style="margin: 0px; "><span style="font-size: 13px;"><font face="Lucida Sans">* Is an exception or override set in relying-party.xml configuration for that SP?</font></span></div><div style="margin: 0px; "><span style="font-size: 13px;"><font face="Lucida Sans"><br></font></span></div><div style="margin: 0px; "><span style="font-size: 13px; "><font face="Lucida Sans">* Do you have a suggested strategy/rationale to persuade my vendors to sign requests?</font></span></div><div style="margin: 0px; "><span style="font-size: 13px; "><font face="Lucida Sans"><br></font></span></div><div style="margin: 0px; "><div><span style="font-size: 13px; "><font face="Lucida Sans">* Is this snippet from the "do not edit" portion of the distribution of relying-party.xml where the default requirement is set?</font></span></div><div style="font-family: Helvetica; "><span style="font-size: 13px; "><br></span></div><div><div style="margin: 0px; font-size: 9px; "><span style="font-size: 10px; "><font face="Andale Mono"> <security:SecurityPolicy id="shibboleth.SAML2SSOSecurityPolicy" xsi:type="security:SecurityPolicyType"></font></span></div><div style="margin: 0px; font-size: 9px; "><span style="font-size: 10px; "><font face="Andale Mono"> <security:Rule xsi:type="samlsec:Replay"/></font></span></div><div style="margin: 0px; font-size: 9px; "><span style="font-size: 10px; "><font face="Andale Mono"> <security:Rule xsi:type="samlsec:IssueInstant"/></font></span></div><div style="margin: 0px; font-size: 9px; "><span style="font-size: 10px; "><font face="Andale Mono"> <security:Rule xsi:type="samlsec:SAML2AuthnRequestsSigned"/></font></span></div><div style="margin: 0px; font-size: 9px; "><span style="font-size: 10px; "><font face="Andale Mono"> <security:Rule xsi:type="samlsec:ProtocolWithXMLSignature" trustEngineRef="shibboleth.SignatureTrustEngine" /></font></span></div><div style="margin: 0px; font-size: 9px; "><span style="font-size: 10px; "><font face="Andale Mono"> <security:Rule xsi:type="samlsec:SAML2HTTPRedirectSimpleSign" trustEngineRef="shibboleth.SignatureTrustEngine" /></font></span></div><div style="margin: 0px; font-size: 9px; "><span style="font-size: 10px; "><font face="Andale Mono"> <security:Rule xsi:type="samlsec:SAML2HTTPPostSimpleSign" trustEngineRef="shibboleth.SignatureTrustEngine" /></font></span></div><div style="margin: 0px; font-size: 9px; "><span style="font-size: 10px; "><font face="Andale Mono"> <security:Rule xsi:type="security:ClientCertAuth" trustEngineRef="shibboleth.CredentialTrustEngine" /></font></span></div><div style="margin: 0px; font-size: 9px; "><span style="font-size: 10px; "><font face="Andale Mono"> <security:Rule xsi:type="samlsec:MandatoryIssuer"/></font></span></div><div style="margin: 0px; font-size: 9px; "><span style="font-size: 10px; "><font face="Andale Mono"> </security:SecurityPolicy></font></span></div><div style="font-family: Helvetica; "><span style="font-size: 13px; "><br></span></div></div></div><div style="margin: 0px; font-family: 'Lucida Sans'; "><span style="font-size: 13px;"><br></span></div><div style="margin: 0px; "><span style="font-size: 13px; "><font face="Lucida Sans">Thanks,</font></span></div><div style="margin: 0px; "><span style="font-size: 13px;"><font face="Lucida Sans"><br></font></span></div><div style="margin: 0px; "><span style="font-size: 13px; "><font face="Lucida Sans">David Bantz</font></span></div></body></html>