Opinions on SIDP-570?
David Bantz
dabantz at alaska.edu
Mon Feb 18 15:27:46 EST 2013
On Mon, 18 Feb 2013, at 08:52 , "Cantor, Scott" <cantor.2 at osu.edu> wrote:
> You can't encrypt to an unauthenticated (anonymous) SP, by definition.
> There is absolutely no notion of protecting against spoofing if one allows
> anonymous RP use.
Yes of course*. I was thinking of something pretending to be known service X.
If I provide a SAML response encrypted with X's key, the reply should be
useless to the impostor. Would having the service sign the original request
with its key provide significant additional security (assuming of course I check
the validity of the signature and refuse to proceed with an invalid signature)?
*or at leas I cannot usefully encrypt to an anonymous SP; I could encrypt with a
random key providing a truly useless message.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/dev/attachments/20130218/ef7de39c/attachment-0001.html
More information about the dev
mailing list