<div dir="ltr"><br><div class="gmail_extra"><br><div class="gmail_quote">On Thu, May 28, 2015 at 6:20 AM, Johan Romin <span dir="ltr"><<a href="mailto:johan.romin@egbs.se" target="_blank">johan.romin@egbs.se</a>></span> wrote:</div><div class="gmail_quote"><br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr" style="font-family:Arial;font-size:10.5pt">
<div dir="ltr"><span style="font-size:10.5pt">the service providier requires signed authn request?</span><br></div>

<div dir="ltr">The service provider I'm going to integrate with requires a signed authn request and supports only idp initiated flow.</div><div dir="ltr"><br></div></div></blockquote><div><br></div><div>Other have pointed out the self-defeating nature of that requirement as stated.  But I wonder if the vendor doesn't mean to state that they require the authN assertion from your IdP be signed, rather than, as literally stated, that the unsolicited authN request to the IdP be signed.  </div><div><br></div><div>You craft the unsolicited request to your IdP, and the SAML authN assertion to the vendor's SP is signed by your IdP.  The vendor can check the signature if they've imported the public part of your signing cert.</div><div><br></div><div>Apologies if I've offered a red herring.</div><div><br></div><div>David Bantz</div><div><br></div><div><br></div></div><br></div></div>