Response
The response is signed by HIN. The signature of the response must always be verified to confirm HIN as the source. If this check is not performed, the response could be issued by a potential attacker.
The following values within the response are worth noting:
| Element | Path in XML | Description |
|---|---|---|
AudienceRestriction | /saml2p:Response/saml2:Assertion/saml2:Conditions/saml2:AudienceRestriction | The AudienceRestriction is derived from the AssertionConsumerServiceURL. |
AttributeStatement | /saml2p:Response/saml2:Assertion/saml2:AttributeStatement | The SAML response contains attributes about the HIN Identity. These are included as an AttributeStatement (see Identity Attributes & SAML Assertion). |