SP Requires Signed IdP Cert...
Brent Putman
putmanb at georgetown.edu
Fri Jan 30 16:10:01 EST 2015
On 1/30/15 1:04 AM, Brent Putman wrote:
>
> But yes, I believe we can do this. I'll think about changing the
> defaults on that, for the future. In the meantime, you can have
> control over the global security config via the Spring extension bean
> mentioned here:
>
> https://wiki.shibboleth.net/confluence/display/SHIB2/Changing+IdP+Signature+Method+Algorithm
>
> That page is specifically about configuring SHA-256 signatures, and
> doesn't mention the KeyInfo generation stuff that you need, but the
> same extension class (Spring FactoryBean) does support this. It's a
> bit late here, but tomorrow I will come up with the Spring bean wiring
> config that you'll need, and post it back here and/or on the wiki.
With all the caveats that Scott already mentioned (do you really want to
do this...), the way to get the credential's intermediate certs emitted
in the KeyInfo is:
1) install the extension jar as documented in the above wiki page, and
the extension's doc/INSTALL.txt.
2) But ignore all the stuff about configuring signatures for SHA-256.
Instead use a config snippet in internal.xml like the attached.
Let me know if this doesn't work.
--Brent
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20150130/2ec9f818/attachment.html
-------------- next part --------------
A non-text attachment was scrubbed...
Name: idp-certchain.xml
Type: text/xml
Size: 625 bytes
Desc: not available
Url : http://shibboleth.net/pipermail/users/attachments/20150130/2ec9f818/attachment.xml
More information about the users
mailing list