<div dir="ltr">Closing the loop:<div><br>Replacing the SP metadata with the vendor-corrected version that includes proper KeyDescriptors for both signing and encrypting enabled our IdP to respond with encrypted assertion to nextgen (there are 3 distinctly different X509 certs in the metadata -  for signing, for encryption, and used to sign metadata). <br>A couple quick additional tweaks at the vendor end completed the integration.</div><div><br><div>[So Craig, you might re-visit and hope to encrypt assertions.]</div><div><br></div><div>David Bantz</div><div><br></div></div></div><div class="gmail_extra"><br><div class="gmail_quote">On Fri, Nov 18, 2016 at 9:22 AM, IAM David Bantz <span dir="ltr"><<a href="mailto:dabantz@alaska.edu" target="_blank">dabantz@alaska.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr">Just received totally different metadata from the SP with appropriate keyDesriptors for both signing and encryption;<div>many other enhancements as well such as reflecting properly named requested attributes.</div><div>Clearly I previously received incomplete/bogus metadata.</div><span class="HOEnZb"><font color="#888888"><div><br></div><div>db</div></font></span></div><div class="HOEnZb"><div class="h5"><div class="gmail_extra"><br><div class="gmail_quote">On Fri, Nov 18, 2016 at 9:13 AM, Peter Schober <span dir="ltr"><<a href="mailto:peter.schober@univie.ac.at" target="_blank">peter.schober@univie.ac.at</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">* IAM David Bantz <<a href="mailto:dabantz@alaska.edu" target="_blank">dabantz@alaska.edu</a>> [2016-11-18 19:08]:<br>
<span>> yes, extended discussion with their technical team, who told me<br>
> they'd "turned on" encryption and re-generated the metadata...<br>
<br>
</span>Well, then they should be able to give you a copy of the certificate<br>
you should use for encryption of data to them, either via SAML 2.0<br>
Metadata or out of band. Doesn't really matter at this point.<br>
<br>
(That would make the suggestion moot to try using the cert they signed<br>
their metadata with.)<br>
<br>
You can always find examples of how to mint/assemble metadata in the<br>
Shib wiki and verify with the tools documented on the<br>
MetadataCorrectness wiki page.<br>
<br>
Cheers,<br>
<div class="m_7035488471129741136HOEnZb"><div class="m_7035488471129741136h5">-peter<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.n<wbr>et</a><br>
</div></div></blockquote></div><br></div>
</div></div></blockquote></div><br></div>