using cert in SP metadata for encryption
IAM David Bantz
dabantz at alaska.edu
Thu Nov 17 15:39:46 EST 2016
I've been given metadata for vended service that contains an X509
certificate, but the IdP (v2) does not see it as an encryption key (sends a
SAML status indicating failure to encrypt, with logs indicating no key
encryption credential found for the entity).
The vendor tells me they have "encryption turned on" and confirmed the
metadata. The certificate in the metadata however is fully contained within
<ds:Signature...>...</ds:Signature>. Can / should such a cert be used by
the IdP to encrypt the SAML response?
David Bantz
UA OIT IAM
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20161117/716d3474/attachment-0001.html>
More information about the users
mailing list