<div dir="ltr">Oh, so the thing in the SP's metadata is saying *it* will be signing requests. Sorry - I was confused because it's right in the same place as WantAssertionsSigned="true" - but I suppose I should pay attention to the difference: '<b>want </b>assertions signed' indicating something it expects from the IdP. I see those all have "want..." in them. Duh.<br><div><br></div><div>Thank you! </div><div><br></div><div>Now to tackle their desire to have a NameIDFormat of "unspecified." :-P</div></div><div class="gmail_extra"><br><div class="gmail_quote">On Thu, Feb 25, 2016 at 11:46 AM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="">> I see that the default for all SAML profiles is<br>
><br>
>   signedRequestsPredicate = alwaysFalse<br>
><br>
> I don't know if this is the setting that corresponds to the SP's<br>
> "AuthnRequests" one - so that's my first question.<br>
<br>
</span>It's not related at all. Peter answered the rest. I actually had thought we didn't even look at the flag, but there is a policy rule that should be enforcing it.<br>
<span class="HOEnZb"><font color="#888888"><br>
-- Scott<br>
</font></span><div class="HOEnZb"><div class="h5"><br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br><br clear="all"><div><br></div>-- <br><div class="gmail_signature"><div style="margin-left:40px">Karla Borecky<br>Systems Administrator<br>ITS<br>Smith College<br>Northampton, MA 01063<br></div></div>
</div>