SP signing certificate
Cantor, Scott
cantor.2 at osu.edu
Tue Jul 11 12:43:44 EDT 2017
> As I understand message from SalesForce, they will not sign requests with
> the expired cert; so if you want signed requests, you have to generate a new cert from within
> Salesforce.
> (That may be implicit in what Scott wrote.)
In effect, the mechanics are going to vary, every system will be different.
With any broken SP, not signing requests and where reasonable not encrypting to them are the best bet. Availability is part of security, and running systems with time bombs is not my idea of robust.
-- Scott
More information about the users
mailing list