<div dir="ltr">Thank you for your great support Rod,<div>I will investigate on the configuration which we have done and try to make it proper and solid. </div></div><div class="gmail_extra"><br><div class="gmail_quote">On Mon, Mar 30, 2015 at 3:21 PM, Rod Widdowson <span dir="ltr">&lt;<a href="mailto:rdw@steadingsoftware.com" target="_blank">rdw@steadingsoftware.com</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="">&gt; Thank you Rod, as you mentioned that we don&#39;t have &quot;defaultSigningCredential&quot; and we have the profiles with signAssertions=&quot;never&quot; signResponses=&quot;never&quot;.<br>
<br>
</span><span class="">&gt; 1) What might be the purpose of &lt;X:509-Certificate&gt; in the idp-metadata.xml?<br>
<br>
</span>There is none.  The metadata was generated at install time and then someone removed the use of signing from your configuration and did not update the metadata at that time.   I cannot say who or why, you&#39;ll need to work that out. Things would work just as well if the idp metadata you gave to your SPs didn&#39;t have this bit.<br>
<span class=""><br>
&gt; 2) Are we done improper configuration<br>
<br>
</span>I&#39;ll say &quot;surpising&quot;.<br>
&quot;Improper&quot; I couldn&#39;t say and don&#39;t really feel qualified to comment. Others in this list are and I&#39;d sooner leave that comment to them.<br>
<br>
Equally surprising is that you can find any SPs to communicate with you since they are basically saying that they will take anything that anybody cares to send to them and make an assumption that it is from you, just because the message said it was.<br>
<span class=""><br>
&gt; or Is it because of using own SP not from Shibboleth?<br>
<br>
</span>I am aware that there are some partial SAML implementations out there and I suppose there could be one which functions like that.  It would not be usual to respond to a single SPs misbehavior by turning off all signing for all SPs - it would be like turning of TLS/SSL everywhere because one browser didn’t support it.  The relying party syntax allows you to have per-SP configuration and you would usually turn it off signing for the one SP that didn&#39;t care.<br>
<br>
I would say that you probably need to do some research and work out why you are configured like this.  This is a non standard configuration and someone made it that way.  You need to work out why and then what you should do to deal with that specific situation.<br>
<div class="HOEnZb"><div class="h5"><br>
Rod<br>
<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a></div></div></blockquote></div><br></div>