Signing metadata

Cantor, Scott cantor.2 at osu.edu
Wed Jun 21 14:24:05 EDT 2017


On 6/21/17, 1:59 PM, "users on behalf of Peter Schober" <users-bounces at shibboleth.net on behalf of peter.schober at univie.ac.at> wrote:

> FWIW: Unless there are added subtleties I'm not aware of SimpleSAMLphp
> solved this by having a separate config parameter for the new key (to
> be introduced in a key rollover), combined with special behaviour that
> uses the key from the other/new parameter only for decryption, but not
> for signing:

Yes, that's what would have to be done, but that doesn't help with, say, changing endpoints.

My reluctance is mostly around the fact that the people who want it almost universally intend to just blow off security anyway, which they should be able to do with no help from us. There's a pretty small Venn circle of people wanting to do the right thing but needing more than a script to generate and sign metadata, and the OP may well be in that circle, but it's not a highly populated one.

-- Scott




More information about the users mailing list