<div class="socmaildefaultfont" dir="ltr" style="font-family:Arial;font-size:10.5pt">
<div dir="ltr">Hi!</div>

<div dir="ltr"> </div>

<div dir="ltr">That much I understand, still the service provider doesn't want to change their implementation as they see this as a neccesary feature.</div>

<div dir="ltr">I've tried to alter the metadata on our end not to require a signed authn request and that just passes our end but then halts on the service provider end that then cannot validate our message.</div>

<div dir="ltr">Could this be managed by some kind of initation through a local service provider that I setup on the idp that creates the signeds authn request which in turn gets forwarded to the unsolicited sso servlet?</div>

<div dir="ltr"> </div>

<div dir="ltr"><font face="Default Sans Serif,Verdana,Arial,Helvetica,sans-serif" size="2">Hälsningar / Best Regards<br>
---------------------------------------------------------------<br>
Johan Romin<br>
<br>
Mobil: 070 795 81 28<br>
E-post: <a href="mailto:johan.romin@egbs.se" target="_blank">johan.romin@egbs.se</a><br>
<br>
egbs consulting ab<br>
Dragarbrunnsgatan 46, SE-753 20 Uppsala<br>
Office: +46 18 470 15 40 Helpdesk: +46 18 10 16 90<br>
<a href="http://www.egbs.se" target="_blank">www.egbs.se</a></font>

<div> </div>

<div> </div>

<blockquote data-history-content-modified="1" style="border-left:solid #aaaaaa 2px; margin-left:5px; padding-left:5px; direction:ltr">----- Ursprungligt meddelande -----<br>
Från: Peter Schober <peter.schober@univie.ac.at><br>
Skickades av: "users" <users-bounces@shibboleth.net><br>
Till: users@shibboleth.net<br>
Kopia:<br>
Ärende: Re: Unsoclicited SSO questions<br>
Datum: tors 28 maj 2015 16:30<br>
 
<div><font face="Standard Monospace,Courier New,Courier,monospace" size="2">* Johan Romin <johan.romin@egbs.se> [2015-05-28 16:21]:<br>
> <div dir="ltr">Hi!</div><br>
<br>
Please don't post HTML-only messages to public mailing lists.<br>
<br>
> The service provider I'm going to integrate with requires a signed<br>
> authn request and supports only idp initiated flow.<br>
<br>
An SP sends authn requests (or not, as in this case), an IDP provides<br>
responses (containing assertions).  The above doesn't make any sense,<br>
as a SAML2 authentication request is a SAML protocol message is issued<br>
(and possibly signed) by the SAML Service Provider.<br>
They cannot sign it and not support generating/sending it.<br>
<br>
So that "requirement" just a contradiction in terms.<br>
-peter<br>
--<br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net</font><br>
 </div>
</blockquote>
</div>
</div>