Avoiding signed requests verification by shibboleth IDP

Cantor, Scott cantor.2 at osu.edu
Mon Sep 2 13:33:03 EDT 2013


On 9/2/13 1:25 PM, "kotesh201" <koteshwarv at gmail.com> wrote:
>
>The reason is, I have N number of service providers and they can sign
>using
>different certificates which may be difficult for me to add those many
>certificates in IDP relying-party.xml (as Trust engines ). Can you please
>advise me on this scenario.

Then you put them into the metadata for those SPs. There's no issue with
multiple keys being used, nor does that impact the configuration in any
way.

You do however need to either turn off encryption or explicitly denote the
keys as signing only in the metadata.

-- Scott




More information about the users mailing list