<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:#0563C1;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:#954F72;
        text-decoration:underline;}
pre
        {mso-style-priority:99;
        mso-style-link:"HTML Preformatted Char";
        margin:0in;
        margin-bottom:.0001pt;
        font-size:10.0pt;
        font-family:"Courier New";}
span.HTMLPreformattedChar
        {mso-style-name:"HTML Preformatted Char";
        mso-style-priority:99;
        mso-style-link:"HTML Preformatted";
        font-family:"Courier New";}
p.msonormal0, li.msonormal0, div.msonormal0
        {mso-style-name:msonormal;
        mso-margin-top-alt:auto;
        margin-right:0in;
        mso-margin-bottom-alt:auto;
        margin-left:0in;
        font-size:12.0pt;
        font-family:"Times New Roman",serif;}
span.EmailStyle20
        {mso-style-type:personal;
        font-family:"Calibri",sans-serif;
        color:windowtext;}
span.EmailStyle21
        {mso-style-type:personal-reply;
        font-family:"Calibri",sans-serif;
        color:#1F4E79;
        position:relative;
        top:0pt;
        mso-text-raise:0pt;
        letter-spacing:0pt;
        mso-ligatures:none;
        mso-number-form:default;
        mso-number-spacing:default;
        mso-stylistic-set:0;
        mso-contextual-alternates:no;
        text-decoration:none none;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-size:10.0pt;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="#0563C1" vlink="#954F72">
<div class="WordSection1">
<p class="MsoNormal"><span style="color:#1F4E79">I found the IdP v3 documentation on how to disable assertion signing and encryption by relying party ID, and implemented that temporarily for this SP. This is very handy indeed, and seems to be far more straightforward
 than attempting to decrypt the Response after the fact. <o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F4E79"><a href="https://wiki.shibboleth.net/confluence/display/IDP30/RelyingPartyConfiguration">https://wiki.shibboleth.net/confluence/display/IDP30/RelyingPartyConfiguration</a><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F4E79"><a href="https://wiki.shibboleth.net/confluence/display/IDP30/SecurityConfiguration">https://wiki.shibboleth.net/confluence/display/IDP30/SecurityConfiguration</a>
<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F4E79"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:8.0pt;font-family:"Courier New";color:#1F4E79"><util:list id="shibboleth.RelyingPartyOverrides"><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:8.0pt;font-family:"Courier New";color:#1F4E79"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:8.0pt;font-family:"Courier New";color:#1F4E79">    <!-- temporarily disable signing and encryption for Blackline sandbox -3/5/2016 --><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:8.0pt;font-family:"Courier New";color:#1F4E79">    <bean parent="RelyingPartyByName" c:relyingPartyIds="urn:federation:ssosbna.blacklineondemand.com"><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:8.0pt;font-family:"Courier New";color:#1F4E79">       <property name="profileConfigurations"><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:8.0pt;font-family:"Courier New";color:#1F4E79">            <list><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:8.0pt;font-family:"Courier New";color:#1F4E79">                <bean parent="SAML2.SSO" p:signAssertions="false" p:encryptAssertions="false" /><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:8.0pt;font-family:"Courier New";color:#1F4E79">            </list><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:8.0pt;font-family:"Courier New";color:#1F4E79">        </property><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:8.0pt;font-family:"Courier New";color:#1F4E79">    </bean><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:8.0pt;font-family:"Courier New";color:#1F4E79">   
<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:8.0pt;font-family:"Courier New";color:#1F4E79"></util:list><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F4E79"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#1F4E79">With this I see now in SAML Tracer that the Subject and Name ID are in fact contained in the Response within the EncryptedAssertion element.  Good stuff!<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F4E79"><o:p> </o:p></span></p>
<div>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b>From:</b> users [mailto:users-bounces@shibboleth.net] <b>
On Behalf Of </b>Doan, Tommy<br>
<b>Sent:</b> Saturday, March 5, 2016 10:47 AM<br>
<b>To:</b> 'users@shibboleth.net' <users@shibboleth.net><br>
<b>Subject:</b> Subject missing from Response<o:p></o:p></p>
</div>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">I still have some big gaps in my understanding of SAML requests and responses. Can someone help me understand why I don’t see a SAML Subject in the response below? I expected to see a Subject along with a Name ID in the response, but I
 suspect it’s been signed and encrypted. The following are captures from SAML Tracer. Assuming it has been signed and/or encrypted, what are my options for seeing the values in tools like SAML Tracer or Fiddler? Or do implementers just disable signing and encryption
 temporarily to see these values? <o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
</body>
</html>