default IdP metadata for Shib IdP V3

Tom Scavo trscavo at gmail.com
Tue Jan 19 18:30:18 EST 2016


On Tue, Jan 19, 2016 at 5:58 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:
> On 1/19/16, 5:38 PM, "users on behalf of Tom Scavo" <users-bounces at shibboleth.net on behalf of trscavo at gmail.com> wrote:
>
>>I know what the encryption certificate is for (IdP V3 supports inbound
>>encryption) but why are there two signing certificates?
>
> Separate TLS and signing keys.

That's what I thought. Thanks for confirming.

> We discussed turning off the back channel by default but that didn't win too many yes votes at the time so the metadata still includes all that.

Don't get me started on that topic ;-) Seriously though, in my
experience, SAML security is too complex for the average deployer.
FWIW, I advocate the simplest deployment possible (but no simpler).

Tom


More information about the users mailing list