<html>
  <head>
    <meta content="text/html; charset=windows-1252"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <p><br>
    </p>
    <br>
    <div class="moz-cite-prefix">On 3/10/17 3:29 PM, Yavor Yanakiev
      wrote:<br>
    </div>
    <blockquote
cite="mid:CABracW+eTs_=N9Zn8DFRN+_bhks2c-+XwgJGMxeLpEJYmYZxqA@mail.gmail.com"
      type="cite">
      <div dir="ltr">
        <div><br>
          <div>Since we were able to modify the metadata we
            set AuthnRequestsSigned="false"</div>
          <div><br>
            <md:SPSSODescriptor WantAssertionsSigned="false"
            AuthnRequestsSigned="false"
            protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol"></div>
          <md:KeyDescriptor use="signing"></div>
        <div><br>
        </div>
        <div>but it didn't do the trick. </div>
        <div><br>
        </div>
      </div>
    </blockquote>
    <br>
    Not relevant to your issue, but: for the record that metadata
    attribute doesn't do what you think it does.  It only makes sense to
    set AuthnRequestsSigned="true", which then tells the IdP that
    AuthnRequests from the SP must be signed, or they will be rejected
    outright. It's a statement of policy, basically.<br>
  </body>
</html>