Are SPs without a certificate common?
Tim Larson
Tim.Larson at ucf.edu
Fri Mar 1 11:45:52 EST 2013
I am working with a commercial Service Provider that does not include a public key in the SP metadata and they are saying they don't accept encrypted assertions. They say all they want is the assertion to be signed with the IDP key and everything should pass in the clear.
Is this common and should it be acceptable?
This is the first SP I have encountered that did not include a key and my first thought is to require them to send a key before we do business with them.
Tim Larson
University of Central Florida
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130301/a2180643/attachment.html
More information about the users
mailing list