<div dir="ltr">Hi Peter, <div><br></div><div>By policy, we will use only IDP initiated flow. In that case I have to remove the XML attribute from SP metadata (as only solution).</div><div><br></div><div>Snahasish</div><div class="gmail_extra"><br><div class="gmail_quote">On Tue, Nov 28, 2017 at 11:58 PM, Peter Schober <span dir="ltr"><<a href="mailto:peter.schober@univie.ac.at" target="_blank">peter.schober@univie.ac.at</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">* Santu Ghosh <<a href="mailto:mon.snahasish@gmail.com">mon.snahasish@gmail.com</a>> [2017-11-28 19:20]:<br>
<span class="">> To clarify my understanding from the discussions is that there are<br>
</span>> *ONLY 2* possible<br>
<span class="">> solutions for the mentioned problem.<br>
><br>
</span>> 1) If I want to proceed with unsolicited SSO, I *HAVE TO* remove<br>
> WantAssertionsSigned="true"<br>
> from my SP metadata file *EACH AND EVERY* time before reloading it in IDP.<br>
<span class="">> 2) I can proceed with SP initiated flow, then no modification require in SP<br>
> metadata.<br>
<br>
</span>If the current SP metadata prevents legitimate use on your side (not<br>
that you've explained why IDP-initiated must be used, so far) you can<br>
also just ask the source of the metadata to remove that XML attribute.<br>
<br>
Also note that if you're loading SAML metadata from the SP directly<br>
over http (or https) you're opening up your IDP for all kinds of<br>
security issues. AuthnRequestsSigned being set on that one SP is the<br>
least of your issues then.<br>
<span class="HOEnZb"><font color="#888888"><br>
-peter<br>
</font></span><div class="HOEnZb"><div class="h5">--<br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/<wbr>confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br>
</div></div></blockquote></div><br><div><br></div>
</div></div>