<div dir="auto">I'm new to Shibboleth as of today, and the documentation is a little overwhelming. I was wondering if the following scenario is possible:<div dir="auto"><br></div><div dir="auto">1. SP requires SAML 2.0 assertion for user groups to assign roles, but does not support assertion decryption, nor metadata generation, nor authn request signing</div><div dir="auto">2. IdP mandates assertion encryption and authn request signing</div><div dir="auto">3. Shibboleth hopefully sits in the middle, sending signed authn requests to IdP and decrypted SAML assertions to SP</div><div dir="auto"><br></div><div dir="auto">Ideally I'd like to use mod_shib as the SP already has Apache running. Is there a walkthrough for this kind of scenario or do I just have to keep reading? Or, is this kind of encryption-one-way-but-not-the-other not supported?</div><div dir="auto"><br></div><div dir="auto">Thanks,</div></div>