unencrypted assertions not working

Christopher Bongaarts cab at umn.edu
Wed Apr 3 11:11:36 EDT 2013


On 4/3/2013 9:21 AM, Mark K. Miller wrote:
> During new engagements I've had many SPs come back to me with this
> 'requirement.'  I tell them, in my opinion, it is not a best practice,
> and refuse to do it.  I have them configure their SP to handle encrypted
> assertions.

I usually go along with the SP in these cases.  Now, if they happen to 
be using Shibboleth for their SP software, I'd probably push back, as 
supporting encryption is not only "easy" (FSD) but the "default" and 
they've probably borked their install if they don't have one.  But most 
of the time they're using non-Shibboleth software whose encryption 
support is either lacking or difficult to set up correctly.  If you 
(users@, not just Max) know how to do this easily for non-Shib SPs, 
please consider documenting them on the Shib wiki Commercial Interop page...

I don't *like* it, as it means updating my relying-party file which I 
wouldn't otherwise have to do* (and which due to my IdP version means 
restarting my containers).  But I'd rather have them onboard using 
unencrypted SAML than the alternatives (which in our case never seems to 
include "don't use their service" :/ )

-- 
%%  Christopher A. Bongaarts   %%  cab at umn.edu          %%
%%  OIT - Identity Management  %%  http://umn.edu/~cab  %%
%%  University of Minnesota    %%  +1 (612) 625-1809    %%


More information about the users mailing list