Open tvdijen opened 1 year ago
In addition to https://github.com/OpenConext/OpenConext-engineblock/pull/1231 we see the same incorrect behaviour towards IDPs when an SP uses the key-slug SSO-endpoints.
The default key should always be used for signed AuthnRequests towards IDPs
I cannot reproduce this.
Given:
Then:
@ArnoutvdKnaap Please follow this up
It seems we're able to reproduce it. Will test further.
In addition to https://github.com/OpenConext/OpenConext-engineblock/pull/1231 we see the same incorrect behaviour towards IDPs when an SP uses the key-slug SSO-endpoints.
The default key should always be used for signed AuthnRequests towards IDPs