<div dir="ltr"><div>hi,</div><div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div>
    <p>finnaly it is safe not to encrypt SAML assertions as long a
      signatures are well verified ? <br>
    </p>
    <p></p></div></blockquote><div><br></div><div>signing is meant to ensure that the assertions have not been tampered with - that only works if the SP is actually doing the required checking of the signature....if it isn't then signing will not protect from your observed MITM attacks.  However as for 'safe' , well, that will depend on what is being asserted - as if there is no encryption of the assertion then, whilst they cannot tamper with the assertion, a malevolent actor can still read the assertions and therefore collect potentially private information, PII, group/project/access information etc</div><div><br></div><div>regards</div><div><br></div><div>alan</div></div></div>