Federating with Equifax

Mark K. Miller max at psu.edu
Wed Jan 8 15:03:28 EST 2014


On Wed, 8 Jan 2014, Cantor, Scott wrote:

> As a personal matter, what I would do if I were involved is get the
> existing key signed by a CA, and provide that to Equifax in whatever form
> they demand (I doubt it's metadata). But I wouldn't change my IdP at all.

AMEN to that!  Just because something *can* be done to make something work 
does not prove that it's the optimal thing to do.

Remember when venders told us if we just give them a flat file of all our 
userids and passwords, then access to their service would be simple?  Sure 
it was simple, but how optimal was that?!?!?

The real problem here is that everytime a customer goes off and does the 
silly thing the vendor is requiring, that just makes the vendor all the 
more certain their way is 'right.'  As in this example, where Equifax is 
trying to justify their position by saying other higher-ed sites have 
provided commercial certs.  Well, I say shame on those other higher-ed 
sites for not clearing up the stupididty of the Equifax policy!

> I would first determine whether they even notice the actual cert in the
> message is still the self-signed one. My bet is not. Then I'd laugh and
> ridicule them.

If I don't remember, remind me to buy you a drink the next time we attend 
a conference together!!!

> -- Scott

Thanks,

Max

> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
>


More information about the users mailing list