<html><head><meta http-equiv="content-type" content="text/html; charset=utf-8"></head><body dir="auto">Ok yeah, so I do have the WantAssertionsSigned in the metadata from Duo. It came like that. <div><br></div><div>So I’m really at a loss as to what I’m supposed to do here :-(</div><div><br></div><div>Any suggestions would be greatly appreciated. </div><div><br></div><div><div dir="ltr"><div><span class="" style="background-color:rgba(255,255,255,0)"><font class=""><b class="">Melvin Lasky</b><br class="">Associate Director of Enterprise Architecture</font><br></span></div><div><span class="" style="background-color:rgba(255,255,255,0)"><a href="x-apple-data-detectors://1/0" dir="ltr" style="text-decoration-color:rgba(128,128,128,0.38)">Riverdale, NY 10471</a><br class="">Phone: <a href="tel:718-862-7410" dir="ltr" style="text-decoration-color:rgba(128,128,128,0.38)">718-862-7410</a><br class=""><a href="mailto:melvin.lasky@manhattan.edu" class="">melvin.lasky@manhattan.edu</a><br class=""><a href="http://www.manhattan.edu/" dir="ltr" style="text-decoration-color:rgba(128,128,128,0.38)">www.manhattan.edu</a></span><br class=""></div></div><div dir="ltr"><br><blockquote type="cite">On Jan 27, 2022, at 6:53 PM, Cantor, Scott <<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>> wrote:<br><br></blockquote></div><blockquote type="cite"><div dir="ltr"><span>Response signing is defaulted, adding p:signAssertions turns that on, as does adding WantAssertionsSigned to the metadata. I don't know that they require signed responses (which would be dumb, that's forcing people to sign twice for no reason) but I tend not to turn it off simply to avoid extra config work since I use the metadata flag to do this, not the relying party approach.</span><br><span></span><br><span>They handle encryption fine.</span><br><span></span><br><span>-- Scott</span><br><span></span><br><span></span><br></div></blockquote></div></body></html>