Are SPs without a certificate common?

Cantor, Scott cantor.2 at osu.edu
Fri Mar 1 12:23:50 EST 2013


On 3/1/13 12:14 PM, "Tim Larson" <Tim.Larson at ucf.edu> wrote:

>Thanks.  That is the feedback I was looking for.
>
>Isn't there something about not having a certificate that keeps you from
>verifying the authentication request actually came from the real SP?

Unless you're requiring signed requests, the only legitimacy is derived
from the validation of the response endpoint.

-- Scott




More information about the users mailing list