<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
</head>
<body>
The metadata is part of the InCommon aggregate. I found this on the
SP's website:<br>
<br>
<div class="ht-container"><i>Q: I realize that Foundry requires the
Assertion of SAML Responses to be signed by the identity
provider. But in the InCommon service provider for my
organization, in </i><i><strong>SPSSODescriptor</strong></i><i>,
you do not have the attribute </i><i><code>WantAssertionsSigned="true"</code></i><i>.
Will you please add this attribute?</i></div>
<i>
</i><i>
</i>
<div class="ht-container"><i>A: It appears that InCommon does not
currently support this metadata attribute. Therefore, you will
need to ensure that your identity provider signs the assertions
for the Foundry service provider.</i></div>
<br>
In my relying-party.xml file for this SP I currently have:<br>
<br>
p:encryptAssertions="false" p:signAssertions="false"
p:signResponses="true"<br>
<br>
Don<br>
<br>
<div class="moz-cite-prefix">On 6/9/20 4:54 PM, Mak, Steve wrote:<br>
</div>
<blockquote type="cite"
cite="mid:E384CED6-F3FD-4B24-9DD5-40FF74E1FCE1@upenn.edu">
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
<meta name="Generator" content="Microsoft Word 15 (filtered
medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:Helvetica;
panose-1:0 0 0 0 0 0 0 0 0 0;}
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
{font-family:"Times New Roman \(Body CS\)";
panose-1:2 2 6 3 5 4 5 2 3 4;}
@font-face
{font-family:Consolas;
panose-1:2 11 6 9 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
margin-bottom:.0001pt;
font-size:11.0pt;
font-family:"Calibri",sans-serif;}
pre
{mso-style-priority:99;
mso-style-link:"HTML Preformatted Char";
margin:0in;
margin-bottom:.0001pt;
font-size:10.0pt;
font-family:"Courier New";}
span.HTMLPreformattedChar
{mso-style-name:"HTML Preformatted Char";
mso-style-priority:99;
mso-style-link:"HTML Preformatted";
font-family:Consolas;}
span.EmailStyle20
{mso-style-type:personal-reply;
font-family:Helvetica;
color:windowtext;
font-weight:normal;
font-style:normal;}
.MsoChpDefault
{mso-style-type:export-only;
font-size:10.0pt;}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
--></style>
<div class="WordSection1">
<p class="MsoNormal"><span style="font-family:Helvetica">It
should take you 1-2 files to be able to determine if you are
signing assertions: relying-party.xml and the
sp-metadata.xml file for their SP.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-family:Helvetica"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-family:Helvetica">relying-party.xml
is where you globally or specifically allow/deny/force
signing.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-family:Helvetica">sp-metadata.xml
file is where an SP can choose to request a signed assertion
if allowed and the IdP doesn't force it.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-family:Helvetica"><o:p> </o:p></span></p>
<div style="border:none;border-top:solid #B5C4DF
1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b><span
style="font-size:12.0pt;color:black">From: </span></b><span
style="font-size:12.0pt;color:black">users
<a class="moz-txt-link-rfc2396E" href="mailto:users-bounces@shibboleth.net"><users-bounces@shibboleth.net></a> on behalf of "Lohr,
Donald" <a class="moz-txt-link-rfc2396E" href="mailto:lohrda@jmu.edu"><lohrda@jmu.edu></a><br>
<b>Reply-To: </b>Shib Users <a class="moz-txt-link-rfc2396E" href="mailto:users@shibboleth.net"><users@shibboleth.net></a><br>
<b>Date: </b>Tuesday, June 9, 2020 at 16:05<br>
<b>To: </b><a class="moz-txt-link-rfc2396E" href="mailto:users@shibboleth.net">"users@shibboleth.net"</a>
<a class="moz-txt-link-rfc2396E" href="mailto:users@shibboleth.net"><users@shibboleth.net></a><br>
<b>Subject: </b>IDP signs the SAML Assertion<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<p class="MsoNormal">I've a SP vendor asking:<br>
<br>
<i>Are you able to go in to your identity provider, go to the
service provider configuration, and ensure that the IDP
signs the SAML Assertion?<br>
</i><br>
How can I actually prove this or not prove it?<br>
<br>
Don<br>
<br>
<o:p></o:p></p>
<pre>-- <o:p></o:p></pre>
<pre>D o n a l d L o h r<o:p></o:p></pre>
<pre>I n f o r m a t i o n S y s t e m s<o:p></o:p></pre>
<pre>J a m e s M a d i s o n U n i v e r s i t y<o:p></o:p></pre>
<pre>5 4 0 . 5 6 8 . 3 7 3 0<o:p></o:p></pre>
</div>
<br>
<fieldset class="mimeAttachmentHeader"></fieldset>
</blockquote>
<br>
<pre class="moz-signature" cols="72">--
D o n a l d L o h r
I n f o r m a t i o n S y s t e m s
J a m e s M a d i s o n U n i v e r s i t y
5 4 0 . 5 6 8 . 3 7 3 0
</pre>
</body>
</html>