Are SPs without a certificate common?

Tim Larson Tim.Larson at ucf.edu
Fri Mar 1 12:14:22 EST 2013


Thanks.  That is the feedback I was looking for.

Isn't there something about not having a certificate that keeps you from verifying the authentication request actually came from the real SP?

Tim

-----Original Message-----
From: users-bounces at shibboleth.net [mailto:users-bounces at shibboleth.net] On Behalf Of Cantor, Scott
Sent: Friday, March 1, 2013 11:56 AM
To: Shib Users
Subject: Re: Are SPs without a certificate common?

On 3/1/13 11:45 AM, "Tim Larson" <Tim.Larson at ucf.edu> wrote:

>I am working with a commercial Service Provider that does not include a 
>public key in the SP metadata and they are saying they don¹t accept 
>encrypted assertions.  They say all they want is the assertion to be 
>signed with the IDP key and  everything should pass in the clear.
> 
>Is this common and should it be acceptable?

Only you can really answer that, it's your data after all. The sad fact is that XML Encryption is pretty broken at this point, and a determined enough attacker can generally recover the data with some work. Most of us don't pass anything worth that kind of effort, but that begs the question why we encrypt it at all and don't just leave it to SSL.

>This is the first SP I have encountered that did not include a key and 
>my first thought is to require them to send a key before we do business 
>with them.

I have more than one, but some of them I forced into InCommon, and that's actually not been such a hot idea because InCommon actually requires a key for an SP. What's worse than not having a key is being forced to get one that won't get used and not understanding any of it.

-- Scott


--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


More information about the users mailing list