SP signing certificate
Hong Ye
hy93 at cornell.edu
Tue Jul 11 09:54:55 EDT 2017
Peter,
Thank you for your quick response. Salesfoce’s signing certificate is going to expire. In their document, they say “If you do SP-initiated SAML and your Identity Provider validates signatures, you must select a new Request Signing Certificate.”. I guess it’s a good practice to use a valid certificate, but not required.
Thanks,
Hong
On 7/11/17, 8:54 AM, "users on behalf of Peter Schober" <users-bounces at shibboleth.net on behalf of peter.schober at univie.ac.at> wrote:
* Hong Ye <hy93 at cornell.edu> [2017-07-11 14:22]:
> Will Shibboleth IDP give error to the AuthnRequests that are signed
> by an expired certificate?
It should not since this would violate the OASIS MetaIOP[1] profile
Shibboleth supports: https://wiki.oasis-open.org/security/SAML2MetadataIOP
You should probably read up on the default trust model involved:
https://wiki.shibboleth.net/confluence/display/CONCEPT/TrustManagement
Alternatively you could be more concrete and describe what behaviour
you're seeing and what behaviour you're expecting. Then we could help
get adjusted either one of those. ;)
-peter
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list