<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; color: rgb(0, 0, 0); font-size: 14px; font-family: Calibri, sans-serif;">
<div>I can see how to turn off encrypting assertions for the Shibboleth IDP by setting the ProfileConfiguration encryptAssertions in the relying-party.xml to &quot;never&quot;. &nbsp;But that means it'll never encryptAssertions for anyone, right? &nbsp;Can I configure the IDP
 to only encryptAssertions to specific Service Providers. &nbsp;</div>
<div><br>
</div>
<div>Or more precisely what I'd like to do it turn encryption of assertions off for a particular service provider that can't seem to handle pulling my login id out of an attribute in the assertion AND decrypting the assertion. &nbsp;However for other service providers
 I'd like to be able to leave encryption of assertions set to &quot;conditional&quot;.</div>
<div><br>
</div>
<div><br>
</div>
<div><br>
</div>
<div><br>
</div>
<br>
<br>
<hr>
<font face="Arial" color="Gray" size="1"><br>
This transmission may contain information that is privileged, confidential, and/or exempt from disclosure under applicable law. If you are not the intended recipient, you are hereby notified that any disclosure, copying, distribution, or use of the information
 contained herein (including any reliance thereon) is strictly prohibited. If you received this transmission in error, please immediately contact the sender and destroy the material in its entirety, whether in electronic or hard copy format.<br>
</font>
</body>
</html>