<div dir="ltr"><div><div>I can confirm that there&#39;s no line break in the actual metadata file, so it must have been an artifact of the email. And there is a signing key present, I just redacted it.<br><br></div>Can you elaborate on the difference (as it relates to Shiboleth) between encrypting the response vs signing the response?<br><br></div>I have the following in my relying-party.xml:<br><br><font size="1"><span style="font-family:monospace,monospace">&lt;rp:DefaultRelyingParty provider=&quot;<a href="https://shib.tc.columbia.edu/idp/shibboleth">https://shib.tc.columbia.edu/idp/shibboleth</a>&quot; defaultSigningCredentialRef=&quot;IdPCredential&quot;&gt;<br>    &lt;!-- <br>        Each attribute in these profiles configuration is set to its default value,<br>        that is, the values that would be in effect if those attributes were not present.<br>        We list them here so that people are aware of them (since they seem reluctant to <br>        read the documentation).<br>    --&gt;<br>    &lt;rp:ProfileConfiguration xsi:type=&quot;saml:ShibbolethSSOProfile&quot;<br>                             includeAttributeStatement=&quot;false&quot;<br>                             assertionLifetime=&quot;PT5M&quot;<br>                             signResponses=&quot;always&quot;<br>                             signAssertions=&quot;always&quot;<br>                             includeConditionsNotBefore=&quot;true&quot;/&gt;<br>                          <br>    &lt;rp:ProfileConfiguration xsi:type=&quot;saml:SAML1AttributeQueryProfile&quot;<br>                             assertionLifetime=&quot;PT5M&quot;<br>                             signResponses=&quot;always&quot;<br>                             signAssertions=&quot;always&quot;<br>                             includeConditionsNotBefore=&quot;true&quot;/&gt;<br>    <br>    &lt;rp:ProfileConfiguration xsi:type=&quot;saml:SAML1ArtifactResolutionProfile&quot;<br>                             signResponses=&quot;always&quot;<br>                             signAssertions=&quot;always&quot;/&gt;<br>    <br>    &lt;rp:ProfileConfiguration xsi:type=&quot;saml:SAML2SSOProfile&quot;<br>                             includeAttributeStatement=&quot;true&quot;<br>                             assertionLifetime=&quot;PT5M&quot;<br>                             assertionProxyCount=&quot;0&quot;<br>                             signResponses=&quot;always&quot;<br>                             signAssertions=&quot;always&quot;<br>                             encryptAssertions=&quot;conditional&quot;<br>                             encryptNameIds=&quot;never&quot;<br>                             includeConditionsNotBefore=&quot;true&quot;/&gt;<br><br>    &lt;rp:ProfileConfiguration xsi:type=&quot;saml:SAML2ECPProfile&quot;<br>                             includeAttributeStatement=&quot;true&quot;<br>                             assertionLifetime=&quot;PT5M&quot;<br>                             assertionProxyCount=&quot;0&quot;<br>                             signResponses=&quot;always&quot;<br>                             signAssertions=&quot;always&quot;<br>                             encryptAssertions=&quot;conditional&quot;<br>                             encryptNameIds=&quot;never&quot;<br>                             includeConditionsNotBefore=&quot;true&quot;/&gt;<br><br>    &lt;rp:ProfileConfiguration xsi:type=&quot;saml:SAML2AttributeQueryProfile&quot; <br>                             assertionLifetime=&quot;PT5M&quot;<br>                             assertionProxyCount=&quot;0&quot;<br>                             signResponses=&quot;always&quot;<br>                             signAssertions=&quot;always&quot;<br>                             encryptAssertions=&quot;conditional&quot;<br>                             encryptNameIds=&quot;never&quot;<br>                             includeConditionsNotBefore=&quot;true&quot;/&gt;<br>    <br>    &lt;rp:ProfileConfiguration xsi:type=&quot;saml:SAML2ArtifactResolutionProfile&quot; <br>                             signResponses=&quot;always&quot;<br>                             signAssertions=&quot;always&quot;<br>                             encryptAssertions=&quot;conditional&quot;<br>                             encryptNameIds=&quot;never&quot;/&gt;<br>    <br>    &lt;rp:ProfileConfiguration xsi:type=&quot;saml:SAML2LogoutRequestProfile&quot;<br>                             signResponses=&quot;always&quot;/&gt;<br><br>&lt;/rp:DefaultRelyingParty&gt;</span></font><br><div><div><div><div class="gmail_extra"><br><div class="gmail_quote">From your comment, I&#39;m assuming that the use=&quot;signing&quot; restriction means that the key can only be used for signing the requests/assertions and not encrypting it. I see above that I have encryptAssertions=&quot;conditional&quot; (<font size="1"><span style="font-family:monospace,monospace">saml:SAML2ECPProfile</span></font>). What determines this conditional behavior? Can I just remove the &quot;signing&quot; restriction?<br><br></div><div class="gmail_quote">Thank you!<br></div><div class="gmail_quote">Teddy<br></div><div class="gmail_quote"><br>On Wed, Mar 11, 2015 at 9:56 AM, Cantor, Scott <span dir="ltr">&lt;<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><span class="">On 3/11/15, 5:31 AM, &quot;Peter Schober&quot; &lt;<a href="mailto:peter.schober@univie.ac.at">peter.schober@univie.ac.at</a>&gt; wrote:<br>
<br>
&gt;* Cantor, Scott &lt;<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>&gt; [2015-03-11 02:31]:<br>
&gt;&gt; On 3/11/15, 1:22 AM, &quot;Sacilowski, Tadeusz&quot; &lt;<a href="mailto:ts2878@tc.columbia.edu">ts2878@tc.columbia.edu</a>&gt; wrote:<br>
&gt;&gt; &gt;This is the metadata generated by ServiceNow (referenced above):<br>
&gt;&gt;<br>
&gt;&gt; Which has no key in it.<br>
&gt;<br>
&gt;To add a bit verbosity to that: The metadata has no key usable for<br>
&gt;encryption in it (note the use=&quot;signing&quot; restriction).<br>
<br>
</span>If there was a signing key, I missed that, but same difference, yes.<br>
<span class=""><font color="#888888"><br>
-- Scott<br>
</font></span><div class=""><div class="h5"><br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br><br clear="all"><br>-- <br><div class="gmail_signature"><div dir="ltr"><b>Tadeusz Sacilowski</b><div><i>Manager, Portal &amp; Mobile Development</i></div><div>Teachers College, Columbia University</div><div><a href="mailto:sacilowski@tc.columbia.edu" target="_blank">sacilowski@tc.columbia.edu</a></div></div></div>
</div></div></div></div></div>