<html>
  <head>
    <meta content="text/html; charset=windows-1252"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <br>
    <br>
    <div class="moz-cite-prefix">On 10/19/15 8:17 PM, Brent Putman
      wrote:<br>
    </div>
    <blockquote cite="mid:5625880A.5050909@georgetown.edu" type="cite">
      <meta content="text/html; charset=windows-1252"
        http-equiv="Content-Type">
      <br>
      <br>
      So yeah, disappointing, I thought this "just worked".  Definitely
      something we need to look at in more depth.  I guess the issue
      could be on either end at this point.<br>
    </blockquote>
    <br>
    Doh, eureka!  I just realized that I was only testing the Redirect
    binding simple signature.  I switched the SP to use the POST binding
    with an AuthnRequest signed at the XML level - and it works!  Tried
    a couple of permutations of curves and digest methods, and they all
    work fine.<br>
    <br>
    So the problem is just with the non-XML signature used by the
    Redirect binding.  That at least narrows the problem down.  Still
    doesn't tell us whether the issue is on the IdP or SP end.<br>
    <br>
    Just for fun, I'll see if I can now get the IdP to sign with ECDSA
    and whether the SP accepts it... <br>
    <br>
     <br>
  </body>
</html>