unencrypted assertions not working
Christopher Bongaarts
cab at umn.edu
Wed Apr 3 11:11:36 EDT 2013
On 4/3/2013 9:21 AM, Mark K. Miller wrote:
> During new engagements I've had many SPs come back to me with this
> 'requirement.' I tell them, in my opinion, it is not a best practice,
> and refuse to do it. I have them configure their SP to handle encrypted
> assertions.
I usually go along with the SP in these cases. Now, if they happen to
be using Shibboleth for their SP software, I'd probably push back, as
supporting encryption is not only "easy" (FSD) but the "default" and
they've probably borked their install if they don't have one. But most
of the time they're using non-Shibboleth software whose encryption
support is either lacking or difficult to set up correctly. If you
(users@, not just Max) know how to do this easily for non-Shib SPs,
please consider documenting them on the Shib wiki Commercial Interop page...
I don't *like* it, as it means updating my relying-party file which I
wouldn't otherwise have to do* (and which due to my IdP version means
restarting my containers). But I'd rather have them onboard using
unencrypted SAML than the alternatives (which in our case never seems to
include "don't use their service" :/ )
--
%% Christopher A. Bongaarts %% cab at umn.edu %%
%% OIT - Identity Management %% http://umn.edu/~cab %%
%% University of Minnesota %% +1 (612) 625-1809 %%
More information about the users
mailing list