SP signing certificate

Cantor, Scott cantor.2 at osu.edu
Tue Jul 11 11:10:39 EDT 2017


> Thank you for your quick response. Salesfoce’s signing certificate is going to
> expire. In their document, they say “If you do SP-initiated SAML and your
> Identity Provider validates signatures, you must select a new Request Signing
> Certificate.”. I guess it’s a good practice to use a valid certificate, but not
> required.

Just because Shibboleth doesn't break doesn't mean SalesForce won't. The systems using the keys typically enforce the same inappropriate rules on themselves, which is even dumber than the recipient doing it, so chances are it will break.

That's why if you see a short term cert for encryption you're probably advised to consider whether you really want to turn on encryption, or expect to manually manage the rollover on some arbitrary schedule.

I just federated with Oracle's cloud stuff, and they have a cert expiring in 2019. I left encryption on, but they use the same key for signing their requests (which I can't turn off) so no matter what I do, I'm either around in 2019 or it breaks.

-- Scott



More information about the users mailing list