<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
  </head>
  <body>
    The metadata is part of the InCommon aggregate. I found this on the
    SP's website:<br>
    <br>
    <div class="ht-container"><i>Q: I realize that Foundry requires the
        Assertion of SAML Responses to be signed by the identity
        provider. But in the InCommon service provider for my
        organization, in </i><i><strong>SPSSODescriptor</strong></i><i>,
        you do not have the attribute </i><i><code>WantAssertionsSigned="true"</code></i><i>.
        Will you please add this attribute?</i></div>
    <i>
    </i><i>
    </i>
    <div class="ht-container"><i>A: It appears that InCommon does not
        currently support this metadata attribute. Therefore, you will
        need to ensure that your identity provider signs the assertions
        for the Foundry service provider.</i></div>
     <br>
    In my relying-party.xml file for this SP I currently have:<br>
    <br>
    p:encryptAssertions="false" p:signAssertions="false"
    p:signResponses="true"<br>
    <br>
    Don<br>
    <br>
    <div class="moz-cite-prefix">On 6/9/20 4:54 PM, Mak, Steve wrote:<br>
    </div>
    <blockquote type="cite"
      cite="mid:E384CED6-F3FD-4B24-9DD5-40FF74E1FCE1@upenn.edu">
      <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
      <meta name="Generator" content="Microsoft Word 15 (filtered
        medium)">
      <style><!--
/* Font Definitions */
@font-face
        {font-family:Helvetica;
        panose-1:0 0 0 0 0 0 0 0 0 0;}
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:"Times New Roman \(Body CS\)";
        panose-1:2 2 6 3 5 4 5 2 3 4;}
@font-face
        {font-family:Consolas;
        panose-1:2 11 6 9 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}
pre
        {mso-style-priority:99;
        mso-style-link:"HTML Preformatted Char";
        margin:0in;
        margin-bottom:.0001pt;
        font-size:10.0pt;
        font-family:"Courier New";}
span.HTMLPreformattedChar
        {mso-style-name:"HTML Preformatted Char";
        mso-style-priority:99;
        mso-style-link:"HTML Preformatted";
        font-family:Consolas;}
span.EmailStyle20
        {mso-style-type:personal-reply;
        font-family:Helvetica;
        color:windowtext;
        font-weight:normal;
        font-style:normal;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-size:10.0pt;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style>
      <div class="WordSection1">
        <p class="MsoNormal"><span style="font-family:Helvetica">It
            should take you 1-2 files to be able to determine if you are
            signing assertions: relying-party.xml and the
            sp-metadata.xml file for their SP.<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="font-family:Helvetica"><o:p> </o:p></span></p>
        <p class="MsoNormal"><span style="font-family:Helvetica">relying-party.xml
            is where you globally or specifically allow/deny/force
            signing.<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="font-family:Helvetica">sp-metadata.xml
            file is where an SP can choose to request a signed assertion
            if allowed and the IdP doesn't force it.<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="font-family:Helvetica"><o:p> </o:p></span></p>
        <div style="border:none;border-top:solid #B5C4DF
          1.0pt;padding:3.0pt 0in 0in 0in">
          <p class="MsoNormal"><b><span
                style="font-size:12.0pt;color:black">From: </span></b><span
              style="font-size:12.0pt;color:black">users
              <a class="moz-txt-link-rfc2396E" href="mailto:users-bounces@shibboleth.net"><users-bounces@shibboleth.net></a> on behalf of "Lohr,
              Donald" <a class="moz-txt-link-rfc2396E" href="mailto:lohrda@jmu.edu"><lohrda@jmu.edu></a><br>
              <b>Reply-To: </b>Shib Users <a class="moz-txt-link-rfc2396E" href="mailto:users@shibboleth.net"><users@shibboleth.net></a><br>
              <b>Date: </b>Tuesday, June 9, 2020 at 16:05<br>
              <b>To: </b><a class="moz-txt-link-rfc2396E" href="mailto:users@shibboleth.net">"users@shibboleth.net"</a>
              <a class="moz-txt-link-rfc2396E" href="mailto:users@shibboleth.net"><users@shibboleth.net></a><br>
              <b>Subject: </b>IDP signs the SAML Assertion<o:p></o:p></span></p>
        </div>
        <div>
          <p class="MsoNormal"><o:p> </o:p></p>
        </div>
        <p class="MsoNormal">I've a SP vendor asking:<br>
          <br>
          <i>Are you able to go in to your identity provider, go to the
            service provider configuration, and ensure that the IDP
            signs the SAML Assertion?<br>
          </i><br>
          How can I actually prove this or not prove it?<br>
          <br>
          Don<br>
          <br>
          <o:p></o:p></p>
        <pre>-- <o:p></o:p></pre>
        <pre>D o n a l d   L o h r<o:p></o:p></pre>
        <pre>I n f o r m a t i o n   S y s t e m s<o:p></o:p></pre>
        <pre>J a m e s   M a d i s o n   U n i v e r s i t y<o:p></o:p></pre>
        <pre>5 4 0 . 5 6 8 . 3 7 3 0<o:p></o:p></pre>
      </div>
      <br>
      <fieldset class="mimeAttachmentHeader"></fieldset>
    </blockquote>
    <br>
    <pre class="moz-signature" cols="72">-- 
D o n a l d   L o h r
I n f o r m a t i o n   S y s t e m s
J a m e s   M a d i s o n   U n i v e r s i t y
5 4 0 . 5 6 8 . 3 7 3 0
</pre>
  </body>
</html>