Zoom Integration with Shibboleth IdP
Paul Hethmon
paul.hethmon at clareitysecurity.com
Fri Jan 23 09:06:41 EST 2015
On Jan 23, 2015, at 9:01 AM, Tom Scavo <trscavo at gmail.com> wrote:
>
>> and if signing isn’t enabled it just doesn’t seem secure.
>
> SPs don't sign today so I'm not sure what the concern is. The IdP
> confirms the identity of the SP via trusted metadata so signed
> AuthnRequests are a burden more than anything else. As Scott has said
> a hundred times, an SP that signs AuthnRequests is a sitting duck for
> a DoS attack.
So what’s the attack vector here?
thanks,
Paul
-----
Paul Hethmon
Chief Software Architect
paul.hethmon at clareitysecurity.com
More information about the users
mailing list