SP signing certificate
IAM David Bantz
dabantz at alaska.edu
Tue Jul 11 12:34:08 EDT 2017
As I understand message from SalesForce, they will not sign requests with
the expired cert;
so if you want signed requests, you have to generate a new cert from within
Salesforce.
(That may be implicit in what Scott wrote.)
On Tue, Jul 11, 2017 at 7:10 AM, Cantor, Scott <cantor.2 at osu.edu> wrote:
> > Thank you for your quick response. Salesfoce’s signing certificate is
> going to
> > expire. In their document, they say “If you do SP-initiated SAML and your
> > Identity Provider validates signatures, you must select a new Request
> Signing
> > Certificate.”. I guess it’s a good practice to use a valid certificate,
> but not
> > required.
>
> Just because Shibboleth doesn't break doesn't mean SalesForce won't. The
> systems using the keys typically enforce the same inappropriate rules on
> themselves, which is even dumber than the recipient doing it, so chances
> are it will break.
>
> That's why if you see a short term cert for encryption you're probably
> advised to consider whether you really want to turn on encryption, or
> expect to manually manage the rollover on some arbitrary schedule.
>
> I just federated with Oracle's cloud stuff, and they have a cert expiring
> in 2019. I left encryption on, but they use the same key for signing their
> requests (which I can't turn off) so no matter what I do, I'm either around
> in 2019 or it breaks.
>
> -- Scott
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170711/492c399b/attachment.html>
More information about the users
mailing list