When using the JBoss IDPWebBrowserSSOValve, this feature works as expected. Switching my IdP from using the valve to using the IDPFilter, i no longer get the x509 signature block in my assertions.
To reproduce, configure your idp to add the x509 signature block. Then look at the assertions that are created when using the valve vs. the filter.
See attached files for examples produced using the above steps.
|