<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=utf-8">
  </head>
  <body text="#000000" bgcolor="#FFFFFF">
    <p><br>
    </p>
    <br>
    <div class="moz-cite-prefix">On 5/7/17 12:31 PM, Cantor, Scott
      wrote:<br>
    </div>
    <blockquote type="cite"
      cite="mid:BA50BEA1-DE29-4C7B-8D70-114773FBA825@osu.edu">
      <pre wrap="">
</pre>
      <pre wrap="">
You're looking at the non-errata'd spec, that language was clarified. No SP requiring signed assertions strictly for SSO is behaving appropriately, but if it needs the signature for some subsequent purpose, that's permissible. There's no way this one is.</pre>
    </blockquote>
    <br>
    Ah, right, I forgot to check that.  The errata is very clear, either
    the Response or Assertion may be signed under POST.   Since the
    lightSAML people actually "fixed" this recently per the GitHub issue
    mentioned in the OP's first post, I'll just inform them they need to
    read the errata and reverse.<br>
    <br>
    <br>
    <blockquote type="cite"
      cite="mid:BA50BEA1-DE29-4C7B-8D70-114773FBA825@osu.edu">
      <pre wrap="">
Also, the way to turn on assertion signing like this is really in the metadata anyway. Just add WantAssertionSigned="true" to the SP role. You don't need overrides for it.

</pre>
    </blockquote>
    <br>
    I forgot we had even implemented that.  That's certainly the better
    way if the IdP can modify the SP's metadata.<br>
  </body>
</html>