<html>
<head>
<meta content="text/html; charset=windows-1252"
http-equiv="Content-Type">
</head>
<body bgcolor="#FFFFFF" text="#000000">
<br>
<br>
<div class="moz-cite-prefix">On 10/19/15 8:17 PM, Brent Putman
wrote:<br>
</div>
<blockquote cite="mid:5625880A.5050909@georgetown.edu" type="cite">
<meta content="text/html; charset=windows-1252"
http-equiv="Content-Type">
<br>
<br>
So yeah, disappointing, I thought this "just worked". Definitely
something we need to look at in more depth. I guess the issue
could be on either end at this point.<br>
</blockquote>
<br>
Doh, eureka! I just realized that I was only testing the Redirect
binding simple signature. I switched the SP to use the POST binding
with an AuthnRequest signed at the XML level - and it works! Tried
a couple of permutations of curves and digest methods, and they all
work fine.<br>
<br>
So the problem is just with the non-XML signature used by the
Redirect binding. That at least narrows the problem down. Still
doesn't tell us whether the issue is on the IdP or SP end.<br>
<br>
Just for fun, I'll see if I can now get the IdP to sign with ECDSA
and whether the SP accepts it... <br>
<br>
<br>
</body>
</html>