<html><head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body>
<font face="Helvetica, Arial, sans-serif">Thanks.</font><br>
<br>
<div class="moz-cite-prefix">On 8/2/2023 4:27 PM, Cantor, Scott
wrote:<br>
</div>
<blockquote type="cite" cite="mid:2FC37508-E19D-4BB2-A3A6-D4DC213BA9EC@osu.edu">
<pre class="moz-quote-pre" wrap="">CAUTION: This email originated from outside of JMU. Do not click links or open attachments unless you recognize the sender and know the content is safe.
________________________________
I don't know who's asking you to "prove it" or why, but it bears noting that signing something proves nothing when you have no proof the other end is verifying anything.
The only way to prove anything (at a point in time, since it could change literally a minute later) is to pentest a relying party by modifying a message and checking for failure (and that result is system and implementation dependent so can't easily be automated).
What matters is what the SP does, basically, not what an IdP sends it.
-- Scott
</pre>
</blockquote>
<br>
<pre class="moz-signature" cols="72">--
D o n a l d L o h r
I n f o r m a t i o n S y s t e m s
J a m e s M a d i s o n U n i v e r s i t y
5 4 0 . 5 6 8 . 3 7 3 0
</pre>
</body>
</html>