Next in thread → Next in month →

RE: [security-services] Deflate Sig Alg

From
Scott Cantor <>
Date
2004-12-01T22:08:46+00:00
ID
Thread
RE: [security-services] Deflate Sig Alg
> Hi, perhaps this has been updated (based on cd2), is the 
> signature process based on the url encoded SigAlg value (this 
> is not explicitly stated for this parameter and it stated for 
> RelayState and saml message)?

Do you mean is the parameter URL-encoded before signing? Yes, absolutely. I
meant that you concatenate the query string pieces as they end up and then
sign that string.

I'll try and upload a tweak tonight that explicitly mentions that.

I wanted to have a sample I could include, so if somebody has one, I'm happy
to add it. I did some manual deflates, but I didn't sign them.

-- Scott
Next in thread → Next in month →