【发布时间】:2016-11-26 05:07:39
【问题描述】:
我已经成功部署并运行了 spring saml 示例。从下图的 SAML Response (IdP -> SP) 中,是否可以识别:
- SAML 响应是签名还是未签名?
- 断言是否加密? (我猜它是加密的)
- 断言是有符号还是无符号?
从我的 SP 服务器的调试日志中,在解析上述 SAML 响应之后,可以看到以下内容。这让我对消息和/或断言是否没有签名感到困惑。
- Evaluating security policy of type 'org.opensaml.ws.security.provider.BasicSecurityPolicy' for decoded message
- Evaluating simple signature rule of type: org.opensaml.saml2.binding.security.SAML2HTTPPostSimpleSignRule
- HTTP request was not signed via simple signature mechanism, skipping
- SAML protocol message was not signed, skipping XML signature processing
- Successfully decoded message.
【问题讨论】:
标签: security spring-security saml spring-saml