<div dir="ltr"><div>Thank you guys for the accurate explanations and the links.<br>That helped me quite a lot.<br><br></div><div>Best regards,</div>Larissa<br><div class="gmail_extra"><br><div class="gmail_quote">2017-07-06 9:30 GMT+02:00 Peter Schober <span dir="ltr"><<a href="mailto:peter.schober@univie.ac.at" target="_blank">peter.schober@univie.ac.at</a>></span>:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">* Larissa Riedel <<a href="mailto:larissa.riedel88@gmail.com">larissa.riedel88@gmail.com</a>> [2017-07-05 21:21]:<br>
<span class="">> I try to figure out how the concept of the assertions works.<br>
> Is there an assertion from the SP to the IDP, or is it just a "request"? If<br>
> so, is the assertion encrypted?<br>
<br>
</span>It is just a request from the SP, and that's not encrypted (though the<br>
NameID could, IIRC, though that's not used in practice) and everything<br>
in the request can easily seen in SAML Tracer.<br>
<br>
The request might be signed by the SP, though. The majority don't sign<br>
their requests (because the advantages of signing are debatable) but<br>
it's not that uncommon either.<br>
<br>
Regarding actual assertions (sent from the IDP to the SP) others have<br>
answered that already, I think.<br>
<span class="HOEnZb"><font color="#888888">-peter<br>
</font></span><div class="HOEnZb"><div class="h5">--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br>
</div></div></blockquote></div><br></div></div>