<div dir="ltr">Thanks a lot Steve.<div><br clear="all"><div><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><div dir="ltr">Thanks,<div>Ramkumar Ramasubbu</div><div>CPS</div><div><br></div></div></div></div></div></div><br></div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Thu, Oct 8, 2020 at 6:18 PM Mak, Steve <<a href="mailto:makst@upenn.edu">makst@upenn.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">





<div lang="EN-US" style="overflow-wrap: break-word;">
<div class="gmail-m_-8950193690988112238WordSection1">
<p class="MsoNormal"><span style="font-size:11pt;font-family:Helvetica">Typo fix: <bean parent="SAML2.SSO" … p:encryptAssertions="false"…/></span><span style="font-size:11pt;font-family:Helvetica"><u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11pt;font-family:Helvetica"><u></u> <u></u></span></p>
<div style="border-right:none;border-bottom:none;border-left:none;border-top:1pt solid rgb(181,196,223);padding:3pt 0in 0in">
<p class="MsoNormal"><b><span style="font-family:Calibri,sans-serif;color:black">From:
</span></b><span style="font-family:Calibri,sans-serif;color:black">users <<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a>> on behalf of "Mak, Steve" <<a href="mailto:makst@upenn.edu" target="_blank">makst@upenn.edu</a>><br>
<b>Reply-To: </b>Shib Users <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>><br>
<b>Date: </b>Thursday, October 8, 2020 at 08:45<br>
<b>To: </b>Shib Users <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>><br>
<b>Subject: </b>Re: SAML encryption<u></u><u></u></span></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<p class="MsoNormal"><span style="font-size:11pt;font-family:Helvetica">There would be zero value to sending out a SAML assertion encrypted with the IdP pub cert when the only party that could decrypt/read it would be the IdP.</span><u></u><u></u></p>
<p class="MsoNormal"><span style="font-size:11pt;font-family:Helvetica"> </span><u></u><u></u></p>
<p class="MsoNormal"><span style="font-size:11pt;font-family:Helvetica">Try setting in conf/idp.properties the setting 'idp.encryption.optional = true'.</span><u></u><u></u></p>
<p class="MsoNormal"><span style="font-size:11pt;font-family:Helvetica">Try adding to your DefaultRelyingParty config:</span><u></u><u></u></p>
<p class="MsoNormal"><span style="font-size:11pt;font-family:Helvetica">  <bean parent="SAML2.SSO" … p:encryptAssetions="false"…/></span><u></u><u></u></p>
<p class="MsoNormal"><span style="font-size:11pt;font-family:Helvetica"> </span><u></u><u></u></p>
<div style="border-right:none;border-bottom:none;border-left:none;border-top:1pt solid rgb(181,196,223);padding:3pt 0in 0in">
<p class="MsoNormal"><b><span style="font-family:Calibri,sans-serif;color:black">From:
</span></b><span style="font-family:Calibri,sans-serif;color:black">users <<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a>> on behalf of Ramkumar Ramsubbu <<a href="mailto:ramkumar.ramsubbu.consultant@nielsen.com" target="_blank">ramkumar.ramsubbu.consultant@nielsen.com</a>><br>
<b>Reply-To: </b>Shib Users <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>><br>
<b>Date: </b>Thursday, October 8, 2020 at 08:37<br>
<b>To: </b>Alan Buxey <<a href="mailto:alan.buxey@myunidays.com" target="_blank">alan.buxey@myunidays.com</a>>, Shib Users <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>><br>
<b>Subject: </b>Re: SAML encryption</span><u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"> <u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">Thanks Alan for your quick response.<u></u><u></u></p>
<div>
<p class="MsoNormal"> <u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">Just to verify, we tried to comment all the key sections in the SP Vendor metadata file. Even then the SAML assertion was encrypted. That raised my doubt if IDP's key is used to encrypt.<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><br clear="all">
<u></u><u></u></p>
<div>
<div>
<div>
<div>
<div>
<p class="MsoNormal">Thanks,<u></u><u></u></p>
<div>
<p class="MsoNormal">Ramkumar Ramasubbu<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">CPS<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"> <u></u><u></u></p>
</div>
</div>
</div>
</div>
</div>
</div>
<p class="MsoNormal"> <u></u><u></u></p>
</div>
</div>
<p class="MsoNormal"> <u></u><u></u></p>
<div>
<div>
<p class="MsoNormal">On Thu, Oct 8, 2020 at 6:00 PM Alan Buxey <<a href="mailto:alan.buxey@myunidays.com" target="_blank">alan.buxey@myunidays.com</a>> wrote:<u></u><u></u></p>
</div>
<blockquote style="border-top:none;border-right:none;border-bottom:none;border-left:1pt solid rgb(204,204,204);padding:0in 0in 0in 6pt;margin:5pt 0in 5pt 4.8pt">
<p class="MsoNormal">hi,<br>
><br>
> I am new to SSO implementation. We have a scenario for IDP initiated SSO. We shared the metadata information with our SP & we updated SP metadata in our idp.<br>
> When generating the SAML response, we see SAML assertions are encrypted inside the cipher data tags. I have very basic question here.<br>
><br>
> 1. Which key is used by SSO to encrypt the saml assertion in the response. Is it IDP metadata key or the public key from vendor metadata ?<br>
> 2. We tried to decrypt with an idp private key using an online tool ,we got XML parse error.  Is there any way to decrypt the saml assertions we generate ?<br>
<br>
<br>
its PKI - so its encrypted in the only way that the SP can be the only<br>
one to read it - using the public key from the vendor metadata. only<br>
the SP, with their private key at the the other end, can decrypt it<br>
<br>
alan<u></u><u></u></p>
</blockquote>
</div>
</div>
</div>

-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>