<div dir="ltr">A (new to us) SP provides metadata with a cert and AuthnRequestsSigned="true", but is sending unsigned requests (clearly stated in IdP logs, and verified using samlTracer). I've asserted the SP is misbehaving and reset AuthnRequestsSigned="false" in our metadata cache which enables successful SSO logins. But the vendor is not convinced - alleging other institutions haven't encountered this issue. The service is AbsenceSoft (<span style="font-variant-ligatures:no-common-ligatures;color:rgb(0,0,0);font-family:Menlo;font-size:11px"><a href="https://absencesoft.com">https://absencesoft.com</a>)</span>, and my question to the list is whether you have successfully integrated the "Admin" portal of this service and are receiving signed requests (implicating the SP configuration for our instance). Or if you accommodate their unsigned requests by setting AuthnRequestsSigned="false" (indicating a more general problem for the vendor) or have an IdP config that tolerates their inconsistency (I hope not). [As the IdP operator, I'm OK with the workaround of setting AuthnRequestsSigned="false", particularly since they do consume encrypted responses; but both SP and local service owner continue to pursue.]<div><br></div><div>David St PIerre Bantz</div></div>