<html><head><meta http-equiv="Content-Type" content="text/html charset=us-ascii"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; "><div><span style="font-size: 13px;"><font face="Lucida Sans">I have a vendor that is currently sending unsigned authN requests [having persuaded them to remove an errant X.509 certificate embedded in the request]. &nbsp;My IdP objects that the unsigned request does not meet security requirements (refusing to process it). &nbsp;As this is a service providing electronic signatures for work flow and approval documents, it has seemed to me reasonable and prudent to ask that they digitally sign the authN request to our IdP. &nbsp;</font></span></div><div><span style="font-size: 13px;"><font face="Lucida Sans"><br></font></span></div><div><span style="font-size: 13px;"><font face="Lucida Sans">* Am I off base in asking for signed authN request? &nbsp;Isn't that usual?</font></span></div><div><span style="font-size: 13px;"><font face="Lucida Sans"><br></font></span></div><div><span style="font-size: 13px;"><font face="Lucida Sans">* If they are unable or unwilling [sic!] to sign the SAML authN request, I presume I can configure my IdP to permit unsigned requests from them, but I haven't discovered the documentation for doing so. &nbsp;</font></span></div><div><span style="font-size: 13px;"><font face="Lucida Sans"><br></font></span></div><div style="margin: 0px; "><span style="font-size: 13px;"><font face="Lucida Sans">* Is an exception or override set in relying-party.xml configuration for that SP?</font></span></div><div style="margin: 0px; "><span style="font-size: 13px;"><font face="Lucida Sans"><br></font></span></div><div style="margin: 0px; "><span style="font-size: 13px; "><font face="Lucida Sans">* Do you have a suggested strategy/rationale to persuade my vendors to sign requests?</font></span></div><div style="margin: 0px; "><span style="font-size: 13px; "><font face="Lucida Sans"><br></font></span></div><div style="margin: 0px; "><div><span style="font-size: 13px; "><font face="Lucida Sans">* Is this snippet from the "do not edit" portion of the distribution of relying-party.xml where the default requirement is set?</font></span></div><div style="font-family: Helvetica; "><span style="font-size: 13px; "><br></span></div><div><div style="margin: 0px; font-size: 9px; "><span style="font-size: 10px; "><font face="Andale Mono">&nbsp; &nbsp;&nbsp;&lt;security:SecurityPolicy&nbsp;id="shibboleth.SAML2SSOSecurityPolicy"&nbsp;xsi:type="security:SecurityPolicyType"&gt;</font></span></div><div style="margin: 0px; font-size: 9px; "><span style="font-size: 10px; "><font face="Andale Mono">&nbsp; &nbsp; &nbsp; &nbsp;&nbsp;&lt;security:Rule&nbsp;xsi:type="samlsec:Replay"/&gt;</font></span></div><div style="margin: 0px; font-size: 9px; "><span style="font-size: 10px; "><font face="Andale Mono">&nbsp; &nbsp; &nbsp; &nbsp;&nbsp;&lt;security:Rule&nbsp;xsi:type="samlsec:IssueInstant"/&gt;</font></span></div><div style="margin: 0px; font-size: 9px; "><span style="font-size: 10px; "><font face="Andale Mono">&nbsp; &nbsp; &nbsp; &nbsp;&nbsp;&lt;security:Rule&nbsp;xsi:type="samlsec:SAML2AuthnRequestsSigned"/&gt;</font></span></div><div style="margin: 0px; font-size: 9px; "><span style="font-size: 10px; "><font face="Andale Mono">&nbsp; &nbsp; &nbsp; &nbsp;&nbsp;&lt;security:Rule&nbsp;xsi:type="samlsec:ProtocolWithXMLSignature"&nbsp;trustEngineRef="shibboleth.SignatureTrustEngine"&nbsp;/&gt;</font></span></div><div style="margin: 0px; font-size: 9px; "><span style="font-size: 10px; "><font face="Andale Mono">&nbsp; &nbsp; &nbsp; &nbsp;&nbsp;&lt;security:Rule&nbsp;xsi:type="samlsec:SAML2HTTPRedirectSimpleSign"&nbsp;trustEngineRef="shibboleth.SignatureTrustEngine"&nbsp;/&gt;</font></span></div><div style="margin: 0px; font-size: 9px; "><span style="font-size: 10px; "><font face="Andale Mono">&nbsp; &nbsp; &nbsp; &nbsp;&nbsp;&lt;security:Rule&nbsp;xsi:type="samlsec:SAML2HTTPPostSimpleSign"&nbsp;trustEngineRef="shibboleth.SignatureTrustEngine"&nbsp;/&gt;</font></span></div><div style="margin: 0px; font-size: 9px; "><span style="font-size: 10px; "><font face="Andale Mono">&nbsp; &nbsp; &nbsp; &nbsp;&nbsp;&lt;security:Rule&nbsp;xsi:type="security:ClientCertAuth"&nbsp;trustEngineRef="shibboleth.CredentialTrustEngine"&nbsp;/&gt;</font></span></div><div style="margin: 0px; font-size: 9px; "><span style="font-size: 10px; "><font face="Andale Mono">&nbsp; &nbsp; &nbsp; &nbsp;&nbsp;&lt;security:Rule&nbsp;xsi:type="samlsec:MandatoryIssuer"/&gt;</font></span></div><div style="margin: 0px; font-size: 9px; "><span style="font-size: 10px; "><font face="Andale Mono">&nbsp; &nbsp;&nbsp;&lt;/security:SecurityPolicy&gt;</font></span></div><div style="font-family: Helvetica; "><span style="font-size: 13px; "><br></span></div></div></div><div style="margin: 0px; font-family: 'Lucida Sans'; "><span style="font-size: 13px;"><br></span></div><div style="margin: 0px; "><span style="font-size: 13px; "><font face="Lucida Sans">Thanks,</font></span></div><div style="margin: 0px; "><span style="font-size: 13px;"><font face="Lucida Sans"><br></font></span></div><div style="margin: 0px; "><span style="font-size: 13px; "><font face="Lucida Sans">David Bantz</font></span></div></body></html>