<div dir="ltr"><div><div>OK, setting it to &quot;true&quot; worked for me.  The documentation here should probably be updated because it talks about &quot;always&quot;: <a href="https://wiki.shibboleth.net/confluence/display/IDP30/RelyingPartyConfiguration#RelyingPartyConfiguration-Overrides">https://wiki.shibboleth.net/confluence/display/IDP30/RelyingPartyConfiguration#RelyingPartyConfiguration-Overrides</a><br><br></div>But why do you probably want the response, and not the assertion, signed?  As far as I can tell, SAML2 says that the &quot;Issuer&quot; is only mandatory inside the assertion element (inside the response, it&#39;s optional), and as that&#39;s what we need to be able to trust, surely it&#39;s the assertion that it&#39;s important be signed?<br><br></div>Best regards,<br>Jeremy Morton (Jez)<br></div><div class="gmail_extra"><br><div class="gmail_quote">On Wed, Feb 4, 2015 at 4:29 PM, Cantor, Scott <span dir="ltr">&lt;<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">You probably do *not* want assertions signed, most likely, you should sign responses.<br>
<br>
But &quot;always&quot; is a legacy config setting. For a non-legacy file, just set it to true if that&#39;s what you want. If you want the old &quot;conditional&quot; setting, that requires a bit more than just setting the value to conditional.<br>
<span class="HOEnZb"><font color="#888888"><br>
-- Scott<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</font></span></blockquote></div><br></div>