Configuring Salesforce for Shibboleth IdP (newbie)
Peter Schober
peter.schober at univie.ac.at
Tue Oct 15 08:57:23 EDT 2013
* Tom Scavo <trscavo at gmail.com> [2013-10-14 13:43]:
> On Mon, Oct 14, 2013 at 4:39 AM, David Perry <DPerry at hull-college.ac.uk> wrote:
> > I have heard of places that use this 'public' certificate for the
> > behind the scenes (Idp-SP) channel as well.
>
> That is definitely not recommended since the deployer is then forced
> to migrate certificates in and out of metadata unnecessarily. Although
> certificate migration *can* be done without affecting
> interoperability, in practice it causes breakage all too often.
The mistake then lies with the SP, /thinking/ it is "forced" to
migrate the certificates. We could treat that certificate as just a
public key wrapper, same as with every self-signed one.
To be fair, globally federated SPs often have to adapt to many
differing federations' rules regarding acceptable keys (unless they
can afford to make up their own rules and/or give a damn about
everyone else) and rolling over commercially signed certs every 3
years will "work" with practically everyone (at the cost of causing
work that is uncessary for the vast majority).
-peter
More information about the users
mailing list