I thought Doug stated earlier... &quot;That says its OK for the IDP to use the certificate for encrypted assertions<br>
in addition to box signing requests. The accept the encrypted assertions&quot;<br><br>But if I need to disable this because Box is an SP that doesn&#39;t support encryption, can you explain a little more about how to do this per RP? Is there something I can add to the &lt;MetadataProvider&gt; tag? <br>

<br>-Rob<br><br><br><div class="gmail_quote">On Mon, Jul 8, 2013 at 10:44 AM, Cantor, Scott <span dir="ltr">&lt;<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">

Many commercial SPs don&#39;t handle encryption, that&#39;s up to you to disable per RP in the IdP or decdie to just disable it entirely, as you choose.<br>
<span class="HOEnZb"><font color="#888888"><br>
-- Scott<br>
</font></span><div class="HOEnZb"><div class="h5"><br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br><br clear="all"><br>-- <br><div>Robert W. Gorrell<br>Middleware Engineer, Identity and Access Management</div>
<div>University of NC at Greensboro<br>336-334-5954</div>