"SAML response signature is not valid. "

John Dennis jdennis at redhat.com
Wed Mar 1 12:29:09 EST 2017


On 03/01/2017 11:39 AM, Cantor, Scott wrote:
> Bear in mind that the risk of acquiring metadata from a vendor is not
> that high in relative terms but the risk of a vendor badly acquiring
> the IdP's and doing it insecurely is a data breach of quite likely
> the campus' own data.

Just want to make sure I follow your concerns.

What is the security threat with the IdP metadata? Is it because if it 
was obtained insecurely it might be pointing to a rouge IdP?

How does this lead to a breach of the campus data? Is it because the 
rouge IdP acquired valid campus credentials and then used those 
credentials to access campus data?

-- 
John


More information about the users mailing list