SP signing certificate

Hong Ye hy93 at cornell.edu
Tue Jul 11 09:54:55 EDT 2017


Peter,

Thank you for your quick response. Salesfoce’s signing certificate is going to expire. In their document, they say “If you do SP-initiated SAML and your Identity Provider validates signatures, you must select a new Request Signing Certificate.”. I guess it’s a good practice to use a valid certificate, but not required.  
 
Thanks,
Hong

On 7/11/17, 8:54 AM, "users on behalf of Peter Schober" <users-bounces at shibboleth.net on behalf of peter.schober at univie.ac.at> wrote:

    * Hong Ye <hy93 at cornell.edu> [2017-07-11 14:22]:
    > Will Shibboleth IDP give error to the AuthnRequests that are signed
    > by an expired certificate?
    
    It should not since this would violate the OASIS MetaIOP[1] profile
    Shibboleth supports: https://wiki.oasis-open.org/security/SAML2MetadataIOP
    
    You should probably read up on the default trust model involved:
    https://wiki.shibboleth.net/confluence/display/CONCEPT/TrustManagement
    
    Alternatively you could be more concrete and describe what behaviour
    you're seeing and what behaviour you're expecting. Then we could help
    get adjusted either one of those. ;)
    -peter
    -- 
    To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
    



More information about the users mailing list