Zoom Integration with Shibboleth IdP

Paul Hethmon paul.hethmon at clareitysecurity.com
Fri Jan 23 09:06:41 EST 2015


On Jan 23, 2015, at 9:01 AM, Tom Scavo <trscavo at gmail.com> wrote:
> 
>> and if signing isn’t enabled it just doesn’t seem secure.
> 
> SPs don't sign today so I'm not sure what the concern is. The IdP
> confirms the identity of the SP via trusted metadata so signed
> AuthnRequests are a burden more than anything else. As Scott has said
> a hundred times, an SP that signs AuthnRequests is a sitting duck for
> a DoS attack.

So what’s the attack vector here?

thanks,

Paul


-----
Paul Hethmon
Chief Software Architect
paul.hethmon at clareitysecurity.com




More information about the users mailing list