Skip to content

Conversation

@MingZhang-PS
Copy link

Description

Cert shall not be forced as mandatory parameter for saml assertion signing. It is because the dependent lib xml-crypto only requires private key in order to signing xml document, refer https://github.com/yaronn/xml-crypto#signing-xml-documents. Cert is only used to verify the signature of saml response by assertion consumer.

References

#57

Testing

unit test is added to cover the new functionality

  • [v] This change adds test coverage for new/changed/fixed functionality

Checklist

  • [v] I have added documentation for new/changed functionality in this PR or in auth0.com/docs
  • [v] All active GitHub checks for tests, formatting, and security are passing
  • [v] The correct base branch is being used, if not master

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant