Obnoxious SP (WebMD) Certificate Requirements

Cantor, Scott cantor.2 at osu.edu
Wed Jun 28 17:14:17 EDT 2017


On 6/28/17, 5:04 PM, "users on behalf of Koch, Ken" <users-bounces at shibboleth.net on behalf of ken at wustl.edu> wrote:

> WebMD is refusing to use our IDP certificate, both on technical implementation constraints of a self-signed certificate and
> security-practice reasons. They stated that a 10-year expiration on certificates was irresponsible and not allowed for PHI and
> they adhered to NIST.

You should ask them for a detailed summary of their revocation checking policies and implementation. Also worth asking how exactly they're matching this supposedly trusted certificate issued by a CA against your IdP's actual identity, and where that's documented in any spec. They may *be* doing that, by explicitly configuring a subject name to check, but I've seen just as many PKI conversations like this end in "oh, you're right, I guess we're not checking that". I had one of those conversations years ago with somebody from, umm, NIST.

> (I don’t think that’s possible for
> encryption? Is it? If so, how? I only see signing override options.)

There is almost certainly no encryption involved here, but even if there were, that's based on what's published in metadata or given to the service, and if you really wanted to limit a particular interaction with an SP to support only some decryption keys, you could (but don't need to, it would just try them all). You aren't doing any of this so it's irrelevant.

Obviously I can't help with the actual question. You *can* do whatever is necessary, but can, should, and want to are certainly different. They're wrong, but you know that already.

-- Scott





More information about the users mailing list