what controls assertion signing?
Mark K. Miller
max at psu.edu
Thu Feb 5 19:43:57 EST 2015
On Fri, 6 Feb 2015, Cantor, Scott wrote:
>> If IDP config doesn't trump what others put into metadata you shoulf
>> file a bug, IMO.
>
> It does, in fact. We didn't see it as a bug because metadata is never
> viewed as something somebody can accidentally inject bad data into, it's
> always implicitly trusted.
You do know metadata comes straight from vendors out here in the wild when
we're just testing, right? ;-)
Seriously, though, in the controlled federation scenario, I'd have no need
at all to argue with that explanation.
> Apart from performance, there's no real
> impact to signing them.
>
> We can argue about what "never" should have meant, but that's what Chad
> defined it to mean ("never, except when metadata says to").
>
> That said, I think I completely forgot to implement that flag in V3. So
> my inclination right now is to just define a property for whether to
> honor it, and default it true to match V2 behavior.
You're welcome! ;-)
> -- Scott
>
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list