"SAML response signature is not valid. "
Tom Scavo
trscavo at gmail.com
Wed Mar 1 09:13:46 EST 2017
On Tue, Feb 28, 2017 at 8:11 PM, IAM David Bantz <dabantz at alaska.edu> wrote:
>
> I still have certs that expired in 2014 in the IdP metadata for SPs that
> never consumed the new metadata with new certs in 2014.
That doesn't make sense. There's nothing you can do to your published
metadata to influence SPs that don't consume it.
When you integrate with SPs that do not automatically refresh
metadata, how do they provision your IdP metadata? From the aggregate?
If so, that expired cert is a potential problem since broken SPs will
try use it, fail, and stop.
In any case, you should always pass your metadata to SPs by reference,
never by value. The aggregate makes that kind of difficult, I know.
Once we have per-entity metadata, you will be able to provide a URL
that resolves to your (and only your) IdP metadata. This will make it
easier for SPs (even broken SPs) to automate metadata refresh.
Tom
More information about the users
mailing list