<div dir="ltr">Hi All,<div><br></div><div>I am facing a new problem when I am going to integrate another SP with my IDP for Unsolicited SSO.</div><div><br></div><div> 2017-11-28 16:20:50,040 - ERROR [org.opensaml.saml.saml2.binding.security.impl.SAML2AuthnRequestsSignedSecurityHandler:75] - <span style="background-color:rgb(255,255,0)">SPSSODescriptor for entity ID '<a href="https://shibboleth-sp.xxxxxx.com/shibboleth-sp">https://shibboleth-sp.xxxxxx.com/shibboleth-sp</a>' indicates AuthnRequests must be signed, but inbound message was not signed</span><div>2017-11-28 16:20:50,041 - WARN [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:202] - Profile Action WebFlowMessageHandlerAdaptor: Exception handling message</div><div>org.opensaml.messaging.handler.MessageHandlerException: Inbound AuthnRequest was required to be signed but was not</div><div><span style="white-space:pre"> </span>at org.opensaml.saml.saml2.binding.security.impl.SAML2AuthnRequestsSignedSecurityHandler.doInvoke(SAML2AuthnRequestsSignedSecurityHandler.java:77)</div><div>2017-11-28 16:20:50,051 - WARN [org.opensaml.profile.action.impl.LogEvent:105] - A non-proceed event occurred while processing the request: MessageAuthenticationError</div><div><br></div><div><br></div><div>When I check my SP metadata, I found that <b>AuthnRequestsSigned="true" </b>in my SP metadata.</div><div><br></div><div><div><ds:Signature></div><div> <ds:SignedInfo></div><div> <ds:CanonicalizationMethod Algorithm="<a href="http://www.w3.org/2001/10/xml-exc-c14n#">http://www.w3.org/2001/10/xml-exc-c14n#</a>"/></div><div> <ds:SignatureMethod Algorithm="<a href="http://www.w3.org/2000/09/xmldsig#rsa-sha1">http://www.w3.org/2000/09/xmldsig#rsa-sha1</a>"/></div><div> <ds:Reference URI="#https___shibboleth-sp-dev.betterknow.com_shibboleth-sp"><ds:Transforms><ds:Transform Algorithm="<a href="http://www.w3.org/2000/09/xmldsig#enveloped-signature">http://www.w3.org/2000/09/xmldsig#enveloped-signature</a>"/><ds:Transform Algorithm="<a href="http://www.w3.org/2001/10/xml-exc-c14n#">http://www.w3.org/2001/10/xml-exc-c14n#</a>"/></ds:Transforms><ds:DigestMethod Algorithm="<a href="http://www.w3.org/2000/09/xmldsig#sha1">http://www.w3.org/2000/09/xmldsig#sha1</a>"/><ds:DigestValue>OreU/14CANZdlXlhfpOdBwvjv3E=</ds:DigestValue></ds:Reference></ds:SignedInfo><span style="background-color:rgb(255,255,0)"><ds:SignatureValue></span></div><div><br></div><div><span style="background-color:rgb(255,255,0)"></ds:SignatureValue></span><br></div><div> </ds:X509Certificate></div><div> </ds:X509Data></div><div> </ds:KeyInfo></div><div><span style="background-color:rgb(255,255,0)"></ds:Signature></span><br></div><div><span style="background-color:rgb(255,255,0)"><br></span></div><div><span style="background-color:rgb(255,255,0)"><md:SPSSODescriptor AuthnRequestsSigned="true" WantAssertionsSigned="true" protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol"></span></div></div><div><span style="background-color:rgb(255,255,0)"><br></span></div><div><span style="background-color:rgb(255,255,0)"><br></span></div><div><span style="background-color:rgb(255,255,0)">But in my IDP metadata, there is no </span><span style="background-color:rgb(255,255,0)">AuthnRequestsSigned attribute and there is no signature node.</span></div><div><span style="background-color:rgb(255,255,0)"><br></span></div><div><span style="background-color:rgb(255,255,255)">Can anyone help me, what changes I have to do in my IDP side so that I can proceeded with my SP metadata (with </span><span style="background-color:rgb(255,255,0)">WantAssertionsSigned="true") </span>for Unsolicited SSO.</div><div><span style="background-color:rgb(255,255,0)"><br></span></div><div><span style="background-color:rgb(255,255,0)"><br></span></div><div>-- <br></div><div class="gmail_signature"><div dir="ltr"><div>Snahasish<br><br></div></div></div>
</div></div>