<div class="socmaildefaultfont" dir="ltr" style="font-family:Arial;font-size:10.5pt">
<div dir="ltr">Hi!</div>

<div dir="ltr"> </div>

<div dir="ltr">So now I will try to explain my issue once again a bit more verbose. The service provider metadata SSODescriptior is defined as this:</div>

<div dir="ltr"><md:SPSSODescriptor AuthnRequestsSigned="true" WantAssertionsSigned="true" protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol"></div>

<div dir="ltr"> </div>

<div dir="ltr">This stops shibboleth on the unsolicited servlet and stating that the authn request isn't signed on my end. I cannot find how I change that my authn is signed by the idp.</div>

<div dir="ltr"> </div>

<div dir="ltr">I've read the earlier mail threads and those issues are similar but not the same as mine, if I change the metadata on my idp and change authnrequestsigned="false" the idp forwards the request to the service provider which then is unable to verify the saml response.</div>

<div dir="ltr"> </div>

<div dir="ltr">I am no expert on these things but I think I have missed something in the configuration or misunderstood something I need to setup to get this to work. I've had no issues with other service providers we setup but those are all sp-initiated.</div>

<div dir="ltr"> </div>

<div dir="ltr">I hope this above can help clarify my issue and someone might have insight into what I have missed or misunderstood.</div>

<div dir="ltr"> </div>

<div dir="ltr"> </div>

<div dir="ltr"><font face="Default Sans Serif,Verdana,Arial,Helvetica,sans-serif" size="2">Hälsningar / Best Regards<br>
---------------------------------------------------------------<br>
Johan Romin<br>
<br>
Mobil: 070 795 81 28<br>
E-post: <a href="mailto:johan.romin@egbs.se" target="_blank">johan.romin@egbs.se</a><br>
<br>
egbs consulting ab<br>
Dragarbrunnsgatan 46, SE-753 20 Uppsala<br>
Office: +46 18 470 15 40 Helpdesk: +46 18 10 16 90<br>
<a href="http://www.egbs.se" target="_blank">www.egbs.se</a></font>

<div> </div>

<div> </div>

<blockquote data-history-content-modified="1" style="border-left:solid #aaaaaa 2px; margin-left:5px; padding-left:5px; direction:ltr">----- Ursprungligt meddelande -----<br>
Från: IAM David Bantz <dabantz@alaska.edu><br>
Skickades av: "users" <users-bounces@shibboleth.net><br>
Till: Shib Users <users@shibboleth.net><br>
Kopia:<br>
Ärende: Re: Unsoclicited SSO questions<br>
Datum: fre 29 maj 2015 01:07<br>
 
<div dir="ltr"> 
<div> 
<div>On Thu, May 28, 2015 at 6:20 AM, Johan Romin <span dir="ltr"><<a href="mailto:johan.romin@egbs.se" target="_blank">johan.romin@egbs.se</a>></span> wrote:</div>

<div> 
<blockquote style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div dir="ltr" style="font-family:Arial;font-size:10.5pt">
<div dir="ltr"><span style="font-size:10.5pt">the service providier requires signed authn request?</span></div>

<div dir="ltr">The service provider I'm going to integrate with requires a signed authn request and supports only idp initiated flow.</div>

<div dir="ltr"> </div>
</div>
</blockquote>

<div> </div>

<div>Other have pointed out the self-defeating nature of that requirement as stated.  But I wonder if the vendor doesn't mean to state that they require the authN assertion from your IdP be signed, rather than, as literally stated, that the unsolicited authN request to the IdP be signed.  </div>

<div> </div>

<div>You craft the unsolicited request to your IdP, and the SAML authN assertion to the vendor's SP is signed by your IdP.  The vendor can check the signature if they've imported the public part of your signing cert.</div>

<div> </div>

<div>Apologies if I've offered a red herring.</div>

<div> </div>

<div>David Bantz</div>

<div> </div>

<div> </div>
</div>
</div>
</div>

<div><font face="Standard Monospace,Courier New,Courier,monospace" size="2">--<br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net</font></div>
</blockquote>
</div>
</div>