Shib IdP v3: Which certificate do you upload to InCommon?

Karla Borecky kborecky at smith.edu
Tue Mar 15 13:12:26 EDT 2016


Well, I think we can sum it all up by saying you play the cards you are
dealt. Things aren't always ideal out here in the trenches.

I see in reading the https://wiki.shibboleth.net/confluence/x/VoEOAQ page
(yes! I am reading it! I do want to understand this stuff) that the
encryption certificate is for decrypting stuff coming FROM the SP, which
isn't terribly common. I know for sure we aren't doing anything of the sort
with the three SPs who use our InCommon metadata.

What I did wrong was to assume that the IdP encryption cert was for, you
know, the *IdP* to encrypt assertions and so forth. I did read about the
backchannel cert, to understand what it was, but signing and encryption
seemed pretty self-evident. But they are not. I'm not saying it's OK that I
didn't read that more closely - but I bet I'm not the only person who's
misunderstood this.

The thing is, we don't all have positions devoted to this stuff. We're
usually under the gun to do 88 things at once, and we have to absorb
information as best we can. I do read the shib documentation, and look at
the examples, and research what other people have done. I always want to
follow your advice and do things the right way. But I'm just trying to get
this stuff working.

Karla






On Tue, Mar 15, 2016 at 9:34 AM, Cantor, Scott <cantor.2 at osu.edu> wrote:

> > I agree but I didn't see any way to upload the metadata directly. That
> would
> > have been my preference. If I missed something, please let me know.
>
> Tom's point is that giving people the ability to upload metadata tends to
> result in them grabbing whatever file they have, not understanding what's
> in it, and blindly supplying it.
>
> > I do understand what the three certs are for, but I didn't know which
> one to
> > choose in this case, where it seemed you could only upload one.
>
> InCommon supports any number of keys, but only for signing and TLS, not
> encryption. You can't distinguish between signng and TLS because they're
> both the same in SAML terms.
>
> -- Scott
>
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>



-- 
Karla Borecky
Systems Administrator
ITS
Smith College
Northampton, MA 01063
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160315/364efdc2/attachment.html>


More information about the users mailing list