<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; color: rgb(0, 0, 0); font-size: 14px; font-family: Calibri, sans-serif; ">
<div>Only if they are willing to share their private key with you so you can sign the message.</div>
<div><br>
</div>
<div>Paul</div>
<div><br>
</div>
<span id="OLK_SRC_BODY_SECTION">
<div style="font-family:Calibri; font-size:11pt; text-align:left; color:black; BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 0in; PADDING-RIGHT: 0in; BORDER-TOP: #b5c4df 1pt solid; BORDER-RIGHT: medium none; PADDING-TOP: 3pt">
<span style="font-weight:bold">From: </span>Joy Veronneau &lt;<a href="mailto:jv11@cornell.edu">jv11@cornell.edu</a>&gt;<br>
<span style="font-weight:bold">Reply-To: </span>Shibboleth Users &lt;<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>&gt;<br>
<span style="font-weight:bold">Date: </span>Friday, July 26, 2013 1:09 PM<br>
<span style="font-weight:bold">To: </span>Shibboleth Users &lt;<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>&gt;<br>
<span style="font-weight:bold">Subject: </span>question about IdP initiated SSO<br>
</div>
<div><br>
</div>
<div>
<div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; ">
<div>
<div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; ">
Hi,
<div><br>
</div>
<div>I am working on configuring our IdP (v 2.3.3) with Skillsoft. We want to use IdP initiated SSO, and we also use IdP initiated SSO for some other vendors (WebEx and WorkDay among them.)</div>
<div><br>
</div>
<div>My question centers around using&nbsp;</div>
<div><b style="font-family: 'Times New Roman', serif; font-size: 16px; "><span style="font-size: 11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125); ">AuthnRequestsSigned=&quot;true&quot;</span></b></div>
<div><br>
</div>
<div><font face="Calibri" size="4">in the Skillsoft SP metadata. If I set this to false, then everything works. If I set it to true, as they would like it set, then I get this error on the IdP:</font></div>
<div><font face="Calibri" size="4"><br>
</font></div>
<div><font face="Calibri" size="4">
<div>11:37:28.033 - ERROR [org.opensaml.saml2.binding.security.SAML2AuthnRequestsSignedRule:87] - SPSSODescriptor for entity ID '<a href="https://sso.skillport.com'">https://sso.skillport.com'</a> indicates AuthnRequests must be signed, but inbound message
 was not signed</div>
<div>11:37:28.038 - WARN [edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler:348] - Message did not meet security requirements</div>
<div>org.opensaml.ws.security.SecurityPolicyException: Inbound AuthnRequest was required to be signed but was not</div>
<div><br>
</div>
<div>Is there a way to configure IdP initiated SSO for AuthnRequestsSigned=&quot;true&quot; without breaking our other IdP initiated SSO implementations?</div>
<div><br>
</div>
<div>Thanks,</div>
<div><br>
</div>
<div>Joy</div>
<div><br>
</div>
<div><br>
</div>
</font></div>
</div>
</div>
<br>
</div>
</div>
</span>
</body>
</html>