509 Certificate in Idp-sp communication
Surinaidu Majji
pioneer.suri at gmail.com
Wed Apr 1 00:11:31 EDT 2015
Thank you for your great support Rod,
I will investigate on the configuration which we have done and try to make
it proper and solid.
On Mon, Mar 30, 2015 at 3:21 PM, Rod Widdowson <rdw at steadingsoftware.com>
wrote:
> > Thank you Rod, as you mentioned that we don't have
> "defaultSigningCredential" and we have the profiles with
> signAssertions="never" signResponses="never".
>
> > 1) What might be the purpose of <X:509-Certificate> in the
> idp-metadata.xml?
>
> There is none. The metadata was generated at install time and then
> someone removed the use of signing from your configuration and did not
> update the metadata at that time. I cannot say who or why, you'll need to
> work that out. Things would work just as well if the idp metadata you gave
> to your SPs didn't have this bit.
>
> > 2) Are we done improper configuration
>
> I'll say "surpising".
> "Improper" I couldn't say and don't really feel qualified to comment.
> Others in this list are and I'd sooner leave that comment to them.
>
> Equally surprising is that you can find any SPs to communicate with you
> since they are basically saying that they will take anything that anybody
> cares to send to them and make an assumption that it is from you, just
> because the message said it was.
>
> > or Is it because of using own SP not from Shibboleth?
>
> I am aware that there are some partial SAML implementations out there and
> I suppose there could be one which functions like that. It would not be
> usual to respond to a single SPs misbehavior by turning off all signing for
> all SPs - it would be like turning of TLS/SSL everywhere because one
> browser didn’t support it. The relying party syntax allows you to have
> per-SP configuration and you would usually turn it off signing for the one
> SP that didn't care.
>
> I would say that you probably need to do some research and work out why
> you are configured like this. This is a non standard configuration and
> someone made it that way. You need to work out why and then what you
> should do to deal with that specific situation.
>
> Rod
>
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20150401/a36fb02a/attachment.html
More information about the users
mailing list