Obnoxious SP (WebMD) Certificate Requirements
Paul Caskey
pcaskey at internet2.edu
Wed Jun 28 17:14:40 EDT 2017
A former employer of mine integrated with them several years ago.
They refused to understand our trust model. And I did explain it to them. They would not allow our self-signed cert under any circumstances.
What we ended up doing was horribly insecure and they allowed it because of their lack of understanding. The business relationship didn't last long.
Good luck...
From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Koch, Ken
Sent: Wednesday, June 28, 2017 4:05 PM
To: users at shibboleth.net
Subject: Obnoxious SP (WebMD) Certificate Requirements
Has anyone integrated SAML2 with WebMD? We completed our integration with then a couple years ago and it was completed successfully, requiring a WebMD security override exception for our self-signed IDP certificate.
Last night, we performed an IDP certificate rollover and moved from our 3-year certificate to the now-recommended 10-year InCommon (OASIS SAML2 Metadata Interoperability) standards. https://spaces.internet2.edu/display/InCFederation/X.509+Certificates+in+Metadata
WebMD is refusing to use our IDP certificate, both on technical implementation constraints of a self-signed certificate and security-practice reasons. They stated that a 10-year expiration on certificates was irresponsible and not allowed for PHI and they adhered to NIST.
We're stuck with three options:
- Generate a new CA issued certificate that expires in 3 years and use that for all our SSO
- Generate a new CA issued certificate that expires in 3 years and use that for only WebMD (I don't think that's possible for encryption? Is it? If so, how? I only see signing override options.)
- Disable SAML2 integration with WebMD
____________________________________________________________
Ken Koch | Infrastructure Architect, Enterprise Engineering
Washington University in St. Louis
7425 Forsyth Blvd., Campus Box 1110 | St. Louis, MO 63105
w 314-935-8315 | c 314-223-7256 | ken at wustl.edu<mailto:ken at wustl.edu>
________________________________
The materials in this message are private and may contain Protected Healthcare Information or other information of a sensitive nature. If you are not the intended recipient, be advised that any unauthorized use, disclosure, copying or the taking of any action in reliance on the contents of this information is strictly prohibited. If you have received this email in error, please immediately notify the sender via telephone or return mail.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170628/a79049c1/attachment-0001.html>
More information about the users
mailing list