SP signing certificate
Peter Schober
peter.schober at univie.ac.at
Tue Jul 11 08:54:23 EDT 2017
* Hong Ye <hy93 at cornell.edu> [2017-07-11 14:22]:
> Will Shibboleth IDP give error to the AuthnRequests that are signed
> by an expired certificate?
It should not since this would violate the OASIS MetaIOP[1] profile
Shibboleth supports: https://wiki.oasis-open.org/security/SAML2MetadataIOP
You should probably read up on the default trust model involved:
https://wiki.shibboleth.net/confluence/display/CONCEPT/TrustManagement
Alternatively you could be more concrete and describe what behaviour
you're seeing and what behaviour you're expecting. Then we could help
get adjusted either one of those. ;)
-peter
More information about the users
mailing list