Should SAML authentication responses be signed? #10
Labels
credential authentication
Issue related to credential authentication
identity authentication
Issue related to identity authenticaton
SAML
Issue related to the SAML profiles
The Kantara interop profile now mandates the signing of SAML Response messages while making the signing of Assertions optional. This is the opposite of what the eGov 2.0 (and CATS 2.0) profiles required.
Is there any compelling reason why we should we move CATS in the same direction? Perhaps just for identity authentication?
The text was updated successfully, but these errors were encountered: