using cert in SP metadata for encryption

Craig Pluchinsky craigp at iup.edu
Fri Nov 18 15:15:35 EST 2016


I might.  When I had them enable encryption the metadata didn't change 
and the certs they had in the metadata were set to expire in a couple years.


-------------------------------
Craig Pluchinsky
IT Services
Indiana University of Pennsylvania
724-357-3327


On Fri, 18 Nov 2016, IAM David Bantz wrote:

> Closing the loop:
> Replacing the SP metadata with the vendor-corrected version that includes proper KeyDescriptors for both signing and encrypting enabled our
> IdP to respond with encrypted assertion to nextgen (there are 3 distinctly different X509 certs in the metadata -  for signing, for
> encryption, and used to sign metadata).
> A couple quick additional tweaks at the vendor end completed the integration.
> 
> [So Craig, you might re-visit and hope to encrypt assertions.]
> 
> David Bantz
> 
> 
> On Fri, Nov 18, 2016 at 9:22 AM, IAM David Bantz <dabantz at alaska.edu> wrote:
>       Just received totally different metadata from the SP with appropriate keyDesriptors for both signing and encryption;many other
>       enhancements as well such as reflecting properly named requested attributes.
> Clearly I previously received incomplete/bogus metadata.
> 
> db
> 
> On Fri, Nov 18, 2016 at 9:13 AM, Peter Schober <peter.schober at univie.ac.at> wrote:
>       * IAM David Bantz <dabantz at alaska.edu> [2016-11-18 19:08]:
>       > yes, extended discussion with their technical team, who told me
>       > they'd "turned on" encryption and re-generated the metadata...
>
>       Well, then they should be able to give you a copy of the certificate
>       you should use for encryption of data to them, either via SAML 2.0
>       Metadata or out of band. Doesn't really matter at this point.
>
>       (That would make the suggestion moot to try using the cert they signed
>       their metadata with.)
>
>       You can always find examples of how to mint/assemble metadata in the
>       Shib wiki and verify with the tools documented on the
>       MetadataCorrectness wiki page.
>
>       Cheers,
>       -peter
>       --
>       To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
> 
> 
> 
> 
>


More information about the users mailing list