using cert in SP metadata for encryption
Craig Pluchinsky
craigp at iup.edu
Fri Nov 18 15:15:35 EST 2016
I might. When I had them enable encryption the metadata didn't change
and the certs they had in the metadata were set to expire in a couple years.
-------------------------------
Craig Pluchinsky
IT Services
Indiana University of Pennsylvania
724-357-3327
On Fri, 18 Nov 2016, IAM David Bantz wrote:
> Closing the loop:
> Replacing the SP metadata with the vendor-corrected version that includes proper KeyDescriptors for both signing and encrypting enabled our
> IdP to respond with encrypted assertion to nextgen (there are 3 distinctly different X509 certs in the metadata - for signing, for
> encryption, and used to sign metadata).
> A couple quick additional tweaks at the vendor end completed the integration.
>
> [So Craig, you might re-visit and hope to encrypt assertions.]
>
> David Bantz
>
>
> On Fri, Nov 18, 2016 at 9:22 AM, IAM David Bantz <dabantz at alaska.edu> wrote:
> Just received totally different metadata from the SP with appropriate keyDesriptors for both signing and encryption;many other
> enhancements as well such as reflecting properly named requested attributes.
> Clearly I previously received incomplete/bogus metadata.
>
> db
>
> On Fri, Nov 18, 2016 at 9:13 AM, Peter Schober <peter.schober at univie.ac.at> wrote:
> * IAM David Bantz <dabantz at alaska.edu> [2016-11-18 19:08]:
> > yes, extended discussion with their technical team, who told me
> > they'd "turned on" encryption and re-generated the metadata...
>
> Well, then they should be able to give you a copy of the certificate
> you should use for encryption of data to them, either via SAML 2.0
> Metadata or out of band. Doesn't really matter at this point.
>
> (That would make the suggestion moot to try using the cert they signed
> their metadata with.)
>
> You can always find examples of how to mint/assemble metadata in the
> Shib wiki and verify with the tools documented on the
> MetadataCorrectness wiki page.
>
> Cheers,
> -peter
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
>
>
>
>
>
More information about the users
mailing list