Federating with Equifax
Cantor, Scott
cantor.2 at osu.edu
Wed Jan 8 11:49:39 EST 2014
On 1/8/14, 11:45 AM, "Tom Scavo" <trscavo at gmail.com> wrote:
>On Wed, Jan 8, 2014 at 11:28 AM, Qian, Yi <yqian at ku.edu> wrote:
>>
>> But Equifax insists it is their company policy and they do have
>>federation
>> with some higher education institutions.
>
>Maybe there's a simple miscommunication here...are you sure they're
>talking about the certificate in metadata used to verify the XML
>signature on your SAML assertions? Could they be referring to your
>browser-facing TLS certificate? The latter of course should be issued
>by a trusted CA.
It's unlikely, I've had SPs demand this before, but none have actually
become real projects.
If you have to do it, then that's life, we're just telling the OP to push
back. I don't really understand the question though. Is it not clear how
to do this?
Create a RelyingParty element and define an alternate signing credential.
That's it. Then remember to keep renewing it and deal with the SP breaking
every year because it needs the updated certificate.
-- Scott
More information about the users
mailing list