OpenConext / OpenConext-engineblock

OpenConext SAML 2.0 IdP/SP Gateway
14 stars 22 forks source link

For IDP AuthnRequest force use of EB's default key #1241

Open tvdijen opened 1 year ago

tvdijen commented 1 year ago

In addition to https://github.com/OpenConext/OpenConext-engineblock/pull/1231 we see the same incorrect behaviour towards IDPs when an SP uses the key-slug SSO-endpoints.

The default key should always be used for signed AuthnRequests towards IDPs

thijskh commented 1 year ago

I cannot reproduce this.

Given:

Then:

tvdijen commented 1 year ago

@ArnoutvdKnaap Please follow this up

thijskh commented 1 year ago

It seems we're able to reproduce it. Will test further.