Fixed
Pinned fields
Click on the next to a field label to start pinning.
Details
Details
Assignee
Scott Cantor
Scott CantorReporter
Scott Cantor
Scott CantorComponents
Fix versions
Created April 20, 2009 at 2:17 PM
Updated June 23, 2009 at 12:47 PM
Resolved April 20, 2009 at 2:17 PM
The SAML 2 profile handler wasn't checking the subject confirmation's Recipient attribute because of an error in the policy evaluation step. Audience was still checked, and a separate bug prevented unsigned responses from working properly anyway, so there's little or no security impact at this point.