sp(2.5.5) <-> idp(3.1.2) and ecdsa certs
Brent Putman
putmanb at georgetown.edu
Mon Oct 19 20:35:03 EDT 2015
On 10/19/15 8:17 PM, Brent Putman wrote:
>
>
> So yeah, disappointing, I thought this "just worked". Definitely
> something we need to look at in more depth. I guess the issue could
> be on either end at this point.
Doh, eureka! I just realized that I was only testing the Redirect
binding simple signature. I switched the SP to use the POST binding
with an AuthnRequest signed at the XML level - and it works! Tried a
couple of permutations of curves and digest methods, and they all work fine.
So the problem is just with the non-XML signature used by the Redirect
binding. That at least narrows the problem down. Still doesn't tell us
whether the issue is on the IdP or SP end.
Just for fun, I'll see if I can now get the IdP to sign with ECDSA and
whether the SP accepts it...
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20151019/cb5a4a69/attachment.html>
More information about the users
mailing list