509 Certificate in Idp-sp communication

Rod Widdowson rdw at steadingsoftware.com
Mon Mar 30 05:51:36 EDT 2015


> Thank you Rod, as you mentioned that we don't have "defaultSigningCredential" and we have the profiles with signAssertions="never" signResponses="never".

> 1) What might be the purpose of <X:509-Certificate> in the idp-metadata.xml?

There is none.  The metadata was generated at install time and then someone removed the use of signing from your configuration and did not update the metadata at that time.   I cannot say who or why, you'll need to work that out. Things would work just as well if the idp metadata you gave to your SPs didn't have this bit.

> 2) Are we done improper configuration 

I'll say "surpising".
"Improper" I couldn't say and don't really feel qualified to comment. Others in this list are and I'd sooner leave that comment to them.

Equally surprising is that you can find any SPs to communicate with you since they are basically saying that they will take anything that anybody cares to send to them and make an assumption that it is from you, just because the message said it was.   

> or Is it because of using own SP not from Shibboleth?

I am aware that there are some partial SAML implementations out there and I suppose there could be one which functions like that.  It would not be usual to respond to a single SPs misbehavior by turning off all signing for all SPs - it would be like turning of TLS/SSL everywhere because one browser didn’t support it.  The relying party syntax allows you to have per-SP configuration and you would usually turn it off signing for the one SP that didn't care.

I would say that you probably need to do some research and work out why you are configured like this.  This is a non standard configuration and someone made it that way.  You need to work out why and then what you should do to deal with that specific situation.

Rod




More information about the users mailing list