Are SPs without a certificate common?

Cantor, Scott cantor.2 at osu.edu
Fri Mar 1 11:55:48 EST 2013


On 3/1/13 11:45 AM, "Tim Larson" <Tim.Larson at ucf.edu> wrote:

>I am working with a commercial Service Provider that does not include a
>public key in the SP metadata and they are saying they don¹t accept
>encrypted assertions.  They say all they want is the assertion to be
>signed with the IDP key and
> everything should pass in the clear.
> 
>Is this common and should it be acceptable?

Only you can really answer that, it's your data after all. The sad fact is
that XML Encryption is pretty broken at this point, and a determined
enough attacker can generally recover the data with some work. Most of us
don't pass anything worth that kind of effort, but that begs the question
why we encrypt it at all and don't just leave it to SSL.

>This is the first SP I have encountered that did not include a key and my
>first thought is to require them to send a key before we do business with
>them.

I have more than one, but some of them I forced into InCommon, and that's
actually not been such a hot idea because InCommon actually requires a key
for an SP. What's worse than not having a key is being forced to get one
that won't get used and not understanding any of it.

-- Scott




More information about the users mailing list