<div dir="ltr">If you use ArcGIS Online with Enterprise Logins, encrypted assertions are not supported. You will get errors<br></div><div class="gmail_extra"><br><br><div class="gmail_quote">On Tue, Aug 19, 2014 at 2:55 PM, Nate Klingenstein <span dir="ltr"><<a href="mailto:ndk@internet2.edu" target="_blank">ndk@internet2.edu</a>></span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Max,<br>
<div class=""><br>
> If an implementation claims to support SAML2 but does not support<br>
> encrypted assertions, can that claim be completely correct?<br>
<br>
</div>"Support SAML 2.0" is a vague statement today because the initial normative conformance specifications weren't especially helpful in the first place and they were written a looong time ago. It would be more meaningful to ask them about the SAML2Int work.<br>
<br>
<a href="http://saml2int.org" target="_blank">http://saml2int.org</a><br>
<div class=""><br>
> Phrasing the intent of my question another way (just in case I'm too<br>
> confusing for anyone,) are encrypted assertions part of the SAML protocol<br>
> spec?<br>
<br>
</div>Yes, the encryption is in there. 2.3.4.<br>
<br>
<a href="http://docs.oasis-open.org/security/saml/v2.0/saml-core-2.0-os.pdf" target="_blank">http://docs.oasis-open.org/security/saml/v2.0/saml-core-2.0-os.pdf</a><br>
<br>
Hope this helps,<br>
Nate.<br>
<div class="HOEnZb"><div class="h5">--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br></div>