<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; ">
<div>
<div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; ">
Hi,
<div><br>
</div>
<div>I am working on configuring our IdP (v 2.3.3) with Skillsoft. We want to use IdP initiated SSO, and we also use IdP initiated SSO for some other vendors (WebEx and WorkDay among them.)</div>
<div><br>
</div>
<div>My question centers around using&nbsp;</div>
<div><b style="font-family: 'Times New Roman', serif; font-size: 16px; "><span style="font-size: 11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125); ">AuthnRequestsSigned=&quot;true&quot;</span></b></div>
<div><br>
</div>
<div><font face="Calibri" size="4">in the Skillsoft SP metadata. If I set this to false, then everything works. If I set it to true, as they would like it set, then I get this error on the IdP:</font></div>
<div><font face="Calibri" size="4"><br>
</font></div>
<div><font face="Calibri" size="4">
<div>11:37:28.033 - ERROR [org.opensaml.saml2.binding.security.SAML2AuthnRequestsSignedRule:87] - SPSSODescriptor for entity ID '<a href="https://sso.skillport.com'">https://sso.skillport.com'</a> indicates AuthnRequests must be signed, but inbound message
 was not signed</div>
<div>11:37:28.038 - WARN [edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler:348] - Message did not meet security requirements</div>
<div>org.opensaml.ws.security.SecurityPolicyException: Inbound AuthnRequest was required to be signed but was not</div>
<div><br>
</div>
<div>Is there a way to configure IdP initiated SSO for AuthnRequestsSigned=&quot;true&quot; without breaking our other IdP initiated SSO implementations?</div>
<div><br>
</div>
<div>Thanks,</div>
<div><br>
</div>
<div>Joy</div>
<div><br>
</div>
<div><br>
</div>
</font></div>
</div>
</div>
<br>
</body>
</html>