sp(2.5.5) <-> idp(3.1.2) and ecdsa certs
Cantor, Scott
cantor.2 at osu.edu
Wed Oct 21 10:11:42 EDT 2015
On 10/21/15, 4:25 AM, "users on behalf of Jarno Huuskonen" <users-bounces at shibboleth.net on behalf of jarno.huuskonen at uef.fi> wrote:
>SP can validate xmlsectool.sh (ecdsa) signed metadata if I manually
>remove empty KeyValue from the metadata(signature):
Can you please file a bug on that? The emitting of the empty element in xmlsectool is a bug.
>I changed idp to use ecdsa cert -> SP fails to validate ecdsa signed
>saml2p:Response. (Also xmlsectool.sh and xmlsec1 fail to validate this
>ecdsa signed response:
That's fairly indicative that there's perhaps a regression in Santuario 2.x.
>To summarize what works:
>- SP can verify ecdsa signed metadata
>- SP can send ecdsa signed request to IDP (Post binding)
>
>and doesn't work:
>- IDP fails when SP sends ecdsa signed request to Redirect binding
>- SP fails to verify ecdsa response from IDP
In in both those cases, that's Santuario 2.x computing the signature (to verify it or to create it), so that fits that hypothesis.
-- Scott
More information about the users
mailing list