certificate name was not acceptable

Cantor, Scott cantor.2 at osu.edu
Wed Feb 1 11:16:50 EST 2017


On 2/1/17, 11:07 AM, "users on behalf of William Griffin-Dubson" <users-bounces at shibboleth.net on behalf of wrgriffi at coastal.edu> wrote:

>    I found the issue. The idp-metadata.xml file on our IDP look different from other ones I have seen.

That file doesn't matter in any way. If you're using it for anything and have not thoroughly vetted and populated it in exactly the way you need to, and made it explicitly available in very specific ways in very specific circumstances, you're not using it as intended.

In no case should it be blindly consumed, used unsigned, made available without appropriate validUntil constraints, etc.

In fact, I quite like the idea of us embedding an expired validUntil in there. I don't know why we didn't do that, but we're going to now.

> The first 3 certificates in the IDP metadata are all the same and the bottom 3 are different. I imagine this is a mistake
> made from the person who originally set up our IDP.

That could be, but the fact that it mattered is a strong signal something very, very wrong is being done with the file. Nothing should be directly consuming it.

-- Scott
    



More information about the users mailing list