SP Requires Signed IdP Cert...

Brent Putman putmanb at georgetown.edu
Fri Jan 30 16:10:01 EST 2015


On 1/30/15 1:04 AM, Brent Putman wrote:
>
> But yes, I believe we can do this.  I'll think about changing the
> defaults on that, for the future. In the meantime, you can have
> control over the global security config via the Spring extension bean
> mentioned here:
>
> https://wiki.shibboleth.net/confluence/display/SHIB2/Changing+IdP+Signature+Method+Algorithm
>
> That page is specifically about configuring SHA-256 signatures, and
> doesn't mention the KeyInfo generation stuff that you need, but the
> same extension class (Spring FactoryBean) does support this.  It's a
> bit late here, but tomorrow I will come up with the Spring bean wiring
> config that you'll need, and post it back here and/or on the wiki.

With all the caveats that Scott already mentioned (do you really want to
do this...), the way to get the credential's intermediate certs emitted
in the KeyInfo is:

1) install the extension jar as documented in the above wiki page, and
the extension's doc/INSTALL.txt.

2) But ignore all the stuff about configuring signatures for SHA-256. 
Instead use a config snippet in internal.xml like the attached.


Let me know if this doesn't work.

--Brent



-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20150130/2ec9f818/attachment.html 
-------------- next part --------------
A non-text attachment was scrubbed...
Name: idp-certchain.xml
Type: text/xml
Size: 625 bytes
Desc: not available
Url : http://shibboleth.net/pipermail/users/attachments/20150130/2ec9f818/attachment.xml 


More information about the users mailing list