Ask HN: Should You Include a Certificate in a SAML AuthnRequest?
3•andy89•5h ago
When implementing SAML authentication, one question often arises:Should the Service Provider (SP) include its certificate directly in the <AuthnRequest>?
Comments
stop50•3h ago
Why, the other side should already know it.
oftenwrong•1h ago
I am not an expert in SAML, but my understanding is that the cert is typically included in the SP metadata. It seems to me that icluding the SP cert in the AuthnRequest would defeat the purpose of signing the request. Is that supported in the standard?
stop50•3h ago