Keyboard shortcuts

Press or to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Response

The response is signed by HIN. The signature of the response must always be verified to confirm HIN as the source. If this check is not performed, the response could be issued by a potential attacker.

The following values within the response are worth noting:

ElementPath in XMLDescription
AudienceRestriction/saml2p:Response/saml2:Assertion/saml2:Conditions/saml2:AudienceRestrictionThe AudienceRestriction is derived from the AssertionConsumerServiceURL.
AttributeStatement/saml2p:Response/saml2:Assertion/saml2:AttributeStatementThe SAML response contains attributes about the HIN Identity. These are included as an AttributeStatement (see Identity Attributes & SAML Assertion).