SP signing certificate

Peter Schober peter.schober at univie.ac.at
Tue Jul 11 08:54:23 EDT 2017


* Hong Ye <hy93 at cornell.edu> [2017-07-11 14:22]:
> Will Shibboleth IDP give error to the AuthnRequests that are signed
> by an expired certificate?

It should not since this would violate the OASIS MetaIOP[1] profile
Shibboleth supports: https://wiki.oasis-open.org/security/SAML2MetadataIOP

You should probably read up on the default trust model involved:
https://wiki.shibboleth.net/confluence/display/CONCEPT/TrustManagement

Alternatively you could be more concrete and describe what behaviour
you're seeing and what behaviour you're expecting. Then we could help
get adjusted either one of those. ;)
-peter


More information about the users mailing list