Skip to content

Should SAML authentication responses be signed? #10

@harrdou

Description

@harrdou

The Kantara interop profile now mandates the signing of SAML Response messages while making the signing of Assertions optional. This is the opposite of what the eGov 2.0 (and CATS 2.0) profiles required.

Is there any compelling reason why we should we move CATS in the same direction? Perhaps just for identity authentication?

Metadata

Metadata

Assignees

No one assigned

    Labels

    SAMLIssue related to the SAML profilescredential authenticationIssue related to credential authenticationidentity authenticationIssue related to identity authenticaton

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions