<div dir="ltr">Thanks Scott, that was really helpful in getting me along the right path.  I&#39;ve worked out how to update the relying-parties.xml file and add the metadata extensions so I&#39;m on my way.  And you are completely correct.  Turned out that the problem existed between my keyboard and chair.  I needed the opposite (assertions signed, response open).<div><br></div><div>Thanks</div><div>Marc  </div></div><div class="gmail_extra"><br><div class="gmail_quote">On Wed, Mar 11, 2015 at 12:35 PM, Cantor, Scott <span dir="ltr">&lt;<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="">&gt; &gt; I feel like I&#39;m missing something very obvious so sorry for the dumb<br>
&gt; question.<br>
&gt; &gt; I can&#39;t figure out how to tell Shib  IdP (v3) to sign the response to my SP<br>
&gt; &gt; instead of the assertion.  Its not a standard part of the metadata so is there<br>
&gt; &gt; an extension or something i put into another config file?<br>
&gt;<br>
&gt;<a href="https://wiki.shibboleth.net/confluence/display/IDP30/SecurityConfiguration" target="_blank">https://wiki.shibboleth.net/confluence/display/IDP30/SecurityConfiguration</a><br>
<br>
</span>Also, the default in both SSO profiles is to sign the response, so you shouldn&#39;t have to do anything, actually.<br>
<div class="HOEnZb"><div class="h5"><br>
-- Scott<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br></div>