SP issue: Shib-Identity-Provider not set for some IdPs

Cantor, Scott cantor.2 at osu.edu
Thu Apr 5 19:58:50 BST 2012


On 4/5/12 2:47 PM, "Sara Hopkins" <sara.hopkins at ed.ac.uk> wrote:
>
>Would you be able to point me at the documentation for that bug, please?
>I would be interested to read up on the details to see if it fits the
>problem I'm trying to help with. I've been through the lists of bugs
>fixed in 2.1 and 2.2 but I can't see it.

https://issues.shibboleth.net/jira/browse/SSPCPP-180

The default IdP flags for SAML 2 result in an unsigned response and an
encrypted assertion, which is exactly the trigger for that bug.

I really didn't give it much thought because it's an old bug and if you're
on anything that old, and using SAML 2, you are completely open to the
signature wrapping attack and should have taken your service offline a
long time ago if you don't want to upgrade it.

-- Scott



More information about the users mailing list