SP issue: Shib-Identity-Provider not set for some IdPs
Cantor, Scott
cantor.2 at osu.edu
Thu Apr 5 19:58:50 BST 2012
On 4/5/12 2:47 PM, "Sara Hopkins" <sara.hopkins at ed.ac.uk> wrote:
>
>Would you be able to point me at the documentation for that bug, please?
>I would be interested to read up on the details to see if it fits the
>problem I'm trying to help with. I've been through the lists of bugs
>fixed in 2.1 and 2.2 but I can't see it.
https://issues.shibboleth.net/jira/browse/SSPCPP-180
The default IdP flags for SAML 2 result in an unsigned response and an
encrypted assertion, which is exactly the trigger for that bug.
I really didn't give it much thought because it's an old bug and if you're
on anything that old, and using SAML 2, you are completely open to the
signature wrapping attack and should have taken your service offline a
long time ago if you don't want to upgrade it.
-- Scott
More information about the users
mailing list