what controls assertion signing?
Peter Schober
peter.schober at univie.ac.at
Thu Feb 5 19:39:31 EST 2015
* Cantor, Scott <cantor.2 at osu.edu> [2015-02-06 01:24]:
> It does, in fact. We didn't see it as a bug because metadata is
> never viewed as something somebody can accidentally inject bad data
> into, it's always implicitly trusted.
Yeah, but in general I'd expect to be able to change my IDP's
behaviour by changing its configuration, not having to modify
incoming metadata before it hits my IDP (with all the issues that come
from that).
As for that specific signalling (the SP is likely saying it can only
process this or that type of signing) there's probably no harm in
letting metadata overrule.
-peter
More information about the users
mailing list