Ask HN: Should You Include a Certificate in a SAML AuthnRequest?
4 andy89 2 5/12/2025, 12:20:52 PM
When implementing SAML authentication, one question often arises:Should the Service Provider (SP) include its certificate directly in the <AuthnRequest>?
Comments (2)
oftenwrong · 4h ago
I am not an expert in SAML, but my understanding is that the cert is typically included in the SP metadata. It seems to me that icluding the SP cert in the AuthnRequest would defeat the purpose of signing the request. Is that supported in the standard?
stop50 · 7h ago
Why, the other side should already know it.