SP signing certificate
Peter Schober
peter.schober at univie.ac.at
Wed Jul 12 04:15:49 EDT 2017
* Hong Ye <hy93 at cornell.edu> [2017-07-11 15:55]:
> Thank you for your quick response. Salesfoce’s signing certificate
> is going to expire. In their document, they say “If you do
> SP-initiated SAML and your Identity Provider validates signatures,
Note that "validating signatures" is different from making sure that
the (valid) signature comes from a key that matches a certificate your
IDP has on record /and/ that that certificate fulfills some X.509
validity citeria (e.g. not being expired, or being issued by a trusted
CA, or whatever).
-peter
More information about the users
mailing list