SP Requires Signed IdP Cert...

Andrew Devenish-Meares adevenis at une.edu.au
Sun Feb 1 20:21:31 EST 2015



On 31/01/2015 8:10 AM, Brent Putman wrote:
>
> On 1/30/15 1:04 AM, Brent Putman wrote:
>>
>> But yes, I believe we can do this.  I'll think about changing the
>> defaults on that, for the future. In the meantime, you can have
>> control over the global security config via the Spring extension bean
>> mentioned here:
>>
>> https://wiki.shibboleth.net/confluence/display/SHIB2/Changing+IdP+Signature+Method+Algorithm
>>
>
> With all the caveats that Scott already mentioned (do you really want to
> do this...), the way to get the credential's intermediate certs emitted
> in the KeyInfo is:
>
> 1) install the extension jar as documented in the above wiki page, and
> the extension's doc/INSTALL.txt.
>
> 2) But ignore all the stuff about configuring signatures for SHA-256.
> Instead use a config snippet in internal.xml like the attached.

Hi All,

Thanks for that.  I've installed that and got it working, in terms of 
presenting the certificate chain.  The vendor's server still does not 
accept this, however.  (And yes, I can verify the chain with OpenSSL 
*grin*).

I'm about to pass the caviets back to the product owners with a status 
report, so will see where we go form here.

Thanks for the support

-- 
Andrew Devenish-Meares
Solutions Analyst
Information Technology
University of New England
Armidale   NSW   2351

e:  adevenis at une.edu.au
p:  02 6773 4098
w: http://une.edu.au/itd


More information about the users mailing list