<div dir="ltr"><div>We have Shibboleth IdP v3 (upgraded from v2), member of InCommon. </div><div>Currently we are working with a new vendor who has experience with SAML integrations but not with Shibboleth.</div><div>It seems our vendor (SP) has problems with the way IdP assertion signed and encrypted. No other SPs who are configured to use the same default relying party profile reported problems with assertion encryption performed by our IdP.</div><div>Here is what the vendor says: </div><div>"SP has determined that IdP encrypts the assertion and then signs the encryption</div><div>SP code works as follows: (1) First decrypt the assertion and (2) then compute the signature</div><div>With the signature not inside the encryption SP would need IdP to sign the assertion prior to encryption".</div><div><br></div><div>Are there any options in IdP configuration to control the order. Is there any standard way to encrypt and sigh assertions?</div><div><br></div><div>Thank you,</div><div>Elena </div><div><br></div>
</div>