<html><body><div style="color:#000; background-color:#fff; font-family:times new roman, new york, times, serif;font-size:12pt"><div><span>Turning them off would imply my SP is not a trusted one with the IDP.</span></div><div style="color: rgb(0, 0, 0); font-size: 16px; font-family: 'times new roman', 'new york', times, serif; background-color: transparent; font-style: normal;"><span>It will work but i'm not sure whether there might be any consequences in future.</span></div><div><br></div>  <div style="font-family: 'times new roman', 'new york', times, serif; font-size: 12pt;"> <div style="font-family: 'times new roman', 'new york', times, serif; font-size: 12pt;"> <div dir="ltr"> <hr size="1">  <font size="2" face="Arial"> <b><span style="font-weight:bold;">From:</span></b> Peter Schober &lt;peter.schober@univie.ac.at&gt;<br> <b><span style="font-weight: bold;">To:</span></b> users@shibboleth.net <br> <b><span style="font-weight: bold;">Sent:</span></b>
 Thursday, July 11, 2013 4:21 PM<br> <b><span style="font-weight: bold;">Subject:</span></b> Re: Issue with URL re-direct after IDP authentication -
        signing Assertion<br> </font> </div> <div class="y_msg_container"><br>* justin9 &lt;<a ymailto="mailto:justin9@ymail.com" href="mailto:justin9@ymail.com">justin9@ymail.com</a>&gt; [2013-07-11 22:17]:<br>&gt;&nbsp; &nbsp;  &lt;ns1:Issuer Format="urn:oasis:names:tc:SAML:2.0:nameid-format:entity"<br>&gt; xmlns:ns1="urn:oasis:names:tc:SAML:2.0:assertion"&gt;<a href="https://myidp.org/SAML2/IDP" target="_blank">https://myidp.org/SAML2/IDP</a>&lt;/ns1:Issuer&gt;<br>&gt;&nbsp; &nbsp;  &lt;Status&gt;<br>&gt;&nbsp; &nbsp; &nbsp; &nbsp;  &lt;StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Requester"&gt;<br>&gt;&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;  &lt;StatusCode<br>&gt; Value="urn:oasis:names:tc:SAML:2.0:status:RequestDenied"/&gt;<br>&gt;&nbsp; &nbsp; &nbsp; &nbsp;  &lt;/StatusCode&gt;<br>&gt;&nbsp; &nbsp; &nbsp; &nbsp;  &lt;StatusMessage&gt;Invalid signature.&lt;/StatusMessage&gt;<br>&gt;&nbsp; &nbsp;  &lt;/Status&gt;<br>&gt;
 &lt;/Response&gt;<br><br>Try turning encryption and signing (of authentication requests) off<br>again in your SP, which is what Scott already told you 3 times now.<br><br>No idea why that would not happen on any authentication request from<br>your SP, though.<br>-peter<br>--<br>To unsubscribe from this list send an email to <a ymailto="mailto:users-unsubscribe@shibboleth.net" href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br><br><br></div> </div> </div>  </div></body></html>