Are SPs without a certificate common?

Tim Larson Tim.Larson at ucf.edu
Fri Mar 1 11:45:52 EST 2013


I am working with a commercial Service Provider that does not include a public key in the SP metadata and they are saying they don't accept encrypted assertions.  They say all they want is the assertion to be signed with the IDP key and everything should pass in the clear.

Is this common and should it be acceptable?

This is the first SP I have encountered that did not include a key and my first thought is to require them to send a key before we do business with them.

Tim Larson
University of Central Florida


-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130301/a2180643/attachment.html 


More information about the users mailing list