"SAML response signature is not valid. "
John Dennis
jdennis at redhat.com
Wed Mar 1 12:29:09 EST 2017
On 03/01/2017 11:39 AM, Cantor, Scott wrote:
> Bear in mind that the risk of acquiring metadata from a vendor is not
> that high in relative terms but the risk of a vendor badly acquiring
> the IdP's and doing it insecurely is a data breach of quite likely
> the campus' own data.
Just want to make sure I follow your concerns.
What is the security threat with the IdP metadata? Is it because if it
was obtained insecurely it might be pointing to a rouge IdP?
How does this lead to a breach of the campus data? Is it because the
rouge IdP acquired valid campus credentials and then used those
credentials to access campus data?
--
John
More information about the users
mailing list