Is testshib.org sending a different certificate when returning an Assertion to my SP?
Cantor, Scott
cantor.2 at osu.edu
Wed Apr 17 20:15:37 EDT 2013
On 4/17/13 8:08 PM, "Yaowen Tu" <yaowen.tu at gmail.com> wrote:
>But the response returned to my SP is signed. In the Assertion object,
>the isSigned() flag is true.
You said Response, that's all I was looking at, and it's not signed. I
don't have an SP registered with it, so I can't decrypt the assertion and
see what it's using to sign that with.
>Did I miss anything?
Well, again, I don't see how you can be correct with anybody else being
able to use testshib, including itself. So I'm pretty sure that you have
to be wrong.
But if your statement is that the certificate in the metadata doesn't
match the signature's KeyInfo, the follow on would be "so what?". It
doesn't have to, if the key matches. Perhaps the metadata is out of date
with respect to the certificate but the key's the same. I don't know. That
would at least explain why the cert doesn't match but it still works.
-- Scott
More information about the users
mailing list