<div dir="auto"><div dir="auto"><br></div><div dir="auto">is there other way to solve this issue without modifying SP metadata?</div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Thu, 3 Dec 2020, 8:53 pm Bobby Lawrence, <<a href="mailto:robertl@jlab.org">robertl@jlab.org</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div lang="EN-US" link="blue" vlink="purple">
<div class="m_-1785179153617332578WordSection1">
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif">Yes – if you truly need to do IdP-initiated and the SP cannot (or will not) change their metadata, you should download it, change it locally and then point the IdP at the local
(modified) copy<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif"><u></u> <u></u></span></p>
<p class="MsoNormal" style="margin-left:.5in"><b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif">From:</span></b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif"> users <<a href="mailto:users-bounces@shibboleth.net" target="_blank" rel="noreferrer">users-bounces@shibboleth.net</a>>
<b>On Behalf Of </b>Abhishek Chouksey<br>
<b>Sent:</b> Thursday, December 03, 2020 9:38 AM<br>
<b>To:</b> Shib Users <<a href="mailto:users@shibboleth.net" target="_blank" rel="noreferrer">users@shibboleth.net</a>><br>
<b>Subject:</b> [EXTERNAL] Re: AuthnRequests must be signed, but inbound message was not signed for IDP initiated SSO<u></u><u></u></span></p>
<p class="MsoNormal" style="margin-left:.5in"><u></u> <u></u></p>
<div>
<p class="MsoNormal" style="margin-left:.5in">Means I have to make AuthnRequest flag as false in SP metadata file? :<u></u><u></u></p>
<div>
<p class="MsoNormal" style="margin-left:.5in"><SPSSODescriptor AuthnRequestsSigned="true" WantAssertionsSigned="true" protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:2.0:protocol"><u></u><u></u></p>
</div>
</div>
<p class="MsoNormal" style="margin-left:.5in"><u></u> <u></u></p>
<div>
<div>
<p class="MsoNormal" style="margin-left:.5in">On Thu, Dec 3, 2020 at 7:58 PM Cantor, Scott <<a href="mailto:cantor.2@osu.edu" target="_blank" rel="noreferrer">cantor.2@osu.edu</a>> wrote:<u></u><u></u></p>
</div>
<blockquote style="border:none;border-left:solid #cccccc 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in">
<p class="MsoNormal" style="margin-left:.5in">> Thanks for the reply , but I already gone through that list but unable to figure<br>
> out what is the actual solution ?<br>
<br>
The solution is to fix the metadata.<br>
<br>
-- Scott<br>
<br>
-- <br>
For Consortium Member technical support, see <a href="https://urldefense.proofpoint.com/v2/url?u=https-3A__wiki.shibboleth.net_confluence_x_coFAAg&d=DwMFaQ&c=CJqEzB1piLOyyvZjb8YUQw&r=YbL7Tj_EqBW9abl6xEy1bg&m=rGU52qFMZZ5qhLFP28_MOrx0QLVfWJyR6rUI5f4QzsI&s=Wfz_IBVmVUG9am2riQ6hjBC65kbOFiiFMaXVVpaxm-k&e=" target="_blank" rel="noreferrer">
https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank" rel="noreferrer">
users-unsubscribe@shibboleth.net</a><u></u><u></u></p>
</blockquote>
</div>
</div>
</div>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank" rel="noreferrer">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>