<div dir="ltr">Just received totally different metadata from the SP with appropriate keyDesriptors for both signing and encryption;<div>many other enhancements as well such as reflecting properly named requested attributes.</div><div>Clearly I previously received incomplete/bogus metadata.</div><div><br></div><div>db</div></div><div class="gmail_extra"><br><div class="gmail_quote">On Fri, Nov 18, 2016 at 9:13 AM, Peter Schober <span dir="ltr"><<a href="mailto:peter.schober@univie.ac.at" target="_blank">peter.schober@univie.ac.at</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">* IAM David Bantz <<a href="mailto:dabantz@alaska.edu">dabantz@alaska.edu</a>> [2016-11-18 19:08]:<br>
<span class="">> yes, extended discussion with their technical team, who told me<br>
> they'd "turned on" encryption and re-generated the metadata...<br>
<br>
</span>Well, then they should be able to give you a copy of the certificate<br>
you should use for encryption of data to them, either via SAML 2.0<br>
Metadata or out of band. Doesn't really matter at this point.<br>
<br>
(That would make the suggestion moot to try using the cert they signed<br>
their metadata with.)<br>
<br>
You can always find examples of how to mint/assemble metadata in the<br>
Shib wiki and verify with the tools documented on the<br>
MetadataCorrectness wiki page.<br>
<br>
Cheers,<br>
<div class="HOEnZb"><div class="h5">-peter<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br>
</div></div></blockquote></div><br></div>