<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
        {font-family:SimSun;
        panose-1:2 1 6 0 3 1 1 1 1 1;}
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:"\@SimSun";
        panose-1:2 1 6 0 3 1 1 1 1 1;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0cm;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:#0563C1;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:#954F72;
        text-decoration:underline;}
span.E-MailFormatvorlage17
        {mso-style-type:personal-compose;
        font-family:"Calibri",sans-serif;
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-family:"Calibri",sans-serif;}
@page WordSection1
        {size:612.0pt 792.0pt;
        margin:72.0pt 72.0pt 72.0pt 72.0pt;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="#0563C1" vlink="#954F72">
<div class="WordSection1">
<p class="MsoNormal">Hello,<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">We’ve successfully updated from IdP V2.? to IdP V3.2.1, but now we found an issue in our setup:<o:p></o:p></p>
<p class="MsoNormal">On first login of a user at IdP the AuthnResponse and its Assertion gets both signed and the user gets successfully logged in.<o:p></o:p></p>
<p class="MsoNormal">But when the application’s session expires and the user gets redirected to the IdP again (the session at the IdP is still active), then the IdP generates the AuthnResponse and signs the response but not the assertion….and then the login
 fails because our SP (no shibboleth SP) wants the assertion signed.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">In the SP’s metadata the flag WantAssertionsSigned is set to true.<o:p></o:p></p>
<p class="MsoNormal">Then I tried it with the RelyingParty configuration (like in
<a href="https://wiki.shibboleth.net/confluence/display/IDP30/RelyingPartyConfiguration">
https://wiki.shibboleth.net/confluence/display/IDP30/RelyingPartyConfiguration</a> ).<o:p></o:p></p>
<p class="MsoNormal">In the DefaultRelyingParty bean is set <bean parent="SAML2.SSO" p:signAssertions="true"/>. But it didn’t changed the behavior.<o:p></o:p></p>
<p class="MsoNormal">I also tried to override the profileConfigurations of the RelyingParty by its Id with <bean parent="SAML2.SSO" p:signAssertions="true"/>.  But it also didn’t sign the assertion.<o:p></o:p></p>
<p class="MsoNormal">I also tried it with <bean parent="Shibboleth.SSO" p:signAssertions="true"/>…no success.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Does someone know what I am doing wrong? Is there another configuration which I didn’t found?<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Thanks for your help!<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Greetz Patrick<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
</body>
</html>