Skip to Content.
Sympa Menu

mace-opensaml-users - RE: [OpenSAML] error validating signature on SAML2 EncryptedAssertions decrypted with OpenSAML

Subject: OpenSAML user discussion

List archive

RE: [OpenSAML] error validating signature on SAML2 EncryptedAssertions decrypted with OpenSAML


Chronological Thread 
  • From: "Scott Cantor" <>
  • To: <>
  • Subject: RE: [OpenSAML] error validating signature on SAML2 EncryptedAssertions decrypted with OpenSAML
  • Date: Wed, 19 Nov 2008 10:41:07 -0500
  • Organization: The Ohio State University

> Some cases however require the decrypted Element to exist as part of a
> Document's tree, e.g. ID resolution. So the Decrypter has an option to do
> that. It's turned off by default, b/c it's expensive relatively speaking
> and most cases probably don't require. But signature verification on the
> decrypted Assertion would.

Why is it expensive? I thought Java had adoptNode implemented.

In my case, yes, xmlsec internally re-parses the XML after its been
decrypted.

-- Scott





Archive powered by MHonArc 2.6.16.

Top of Page