off-topic help for Office 365

Cantor, Scott cantor.2 at osu.edu
Wed Feb 17 17:01:06 EST 2016


On 2/17/16, 4:46 PM, "users on behalf of Paul Hethmon" <users-bounces at shibboleth.net on behalf of paul.hethmon at clareitysecurity.com> wrote:


>
>So, to make sure I understand, getting ECP to work requires the TLS certificate be trusted (so signed by a commercial CA) and that the exact same certificate be used to sign the SAML responses?

The former would be expected, sort of (that's basically like a browser-facing cert in real ECP), though in their case they've bastardized ECP such that their proxy shouldn't really need to be relying on that kind of approach.

But if that's the same as the signing cert....yuck. That's a horrid little bug.

-- Scott



More information about the users mailing list