<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; ">
There's not in practice much value to be gained by signing an authentication request because of the other checks in the SAML 2.0 Web Browser SSO profile. If any of those fields is mucked with by the user, it will generally have no practical consequences and/or
cause the request to fail.
<div><br>
</div>
<div>The only major exception, I think, is forceAuthn="true", and an SP can validate the authentication instant to ensure that a fresh authentication was received.
<div><br>
<div>
<div>On Jun 6, 2013, at 0:23 , David Bantz wrote:</div>
<br class="Apple-interchange-newline">
<blockquote type="cite"><span class="Apple-style-span" style="border-collapse: separate; font-family: Helvetica; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; font-size: medium; ">You
also wrote that it's unusual to sign requests, contrary to what I assumed. <br>
Doesn't signing provide some assurance that the message is "real" and thus add value?<br>
</span></blockquote>
</div>
<br>
</div>
</div>
</body>
</html>