SP signing certificate

Hong Ye hy93 at cornell.edu
Tue Jul 11 13:12:52 EDT 2017


Where did you see that?

Here is the note from salesforce

If you do not take the aforementioned actions by August 7, 2017, those features may stop working entirely in your Salesforce environment.
NOTE: Your users will no longer be able to log in to your Salesforce org if you have enabled the following:

  *   SP-initiated SAML configured to sign SAML Requests with the default certificate, and where your IdP is configured to validate the signature on SAML requests.

Sounds like the request will still be signed with the default certificate. If IDP doesn’t validate the signature, then it’s fine. Otherwise, you have to switch to use a new certificate.

From: users <users-bounces at shibboleth.net> on behalf of IAM David Bantz <dabantz at alaska.edu>
Reply-To: Shib Users <users at shibboleth.net>
Date: Tuesday, July 11, 2017 at 12:34 PM
To: Shib Users <users at shibboleth.net>
Subject: Re: SP signing certificate

As I understand message from SalesForce, they will not sign requests with the expired cert;
so if you want signed requests, you have to generate a new cert from within Salesforce.
(That may be implicit in what Scott wrote.)



On Tue, Jul 11, 2017 at 7:10 AM, Cantor, Scott <cantor.2 at osu.edu<mailto:cantor.2 at osu.edu>> wrote:
> Thank you for your quick response. Salesfoce’s signing certificate is going to
> expire. In their document, they say “If you do SP-initiated SAML and your
> Identity Provider validates signatures, you must select a new Request Signing
> Certificate.”. I guess it’s a good practice to use a valid certificate, but not
> required.

Just because Shibboleth doesn't break doesn't mean SalesForce won't. The systems using the keys typically enforce the same inappropriate rules on themselves, which is even dumber than the recipient doing it, so chances are it will break.

That's why if you see a short term cert for encryption you're probably advised to consider whether you really want to turn on encryption, or expect to manually manage the rollover on some arbitrary schedule.

I just federated with Oracle's cloud stuff, and they have a cert expiring in 2019. I left encryption on, but they use the same key for signing their requests (which I can't turn off) so no matter what I do, I'm either around in 2019 or it breaks.

-- Scott

--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net<mailto:users-unsubscribe at shibboleth.net>

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170711/9e89b7b6/attachment.html>


More information about the users mailing list