"SAML response signature is not valid. "

Cantor, Scott cantor.2 at osu.edu
Wed Mar 1 12:35:34 EST 2017


On 3/1/17, 12:29 PM, "users on behalf of John Dennis" <users-bounces at shibboleth.net on behalf of jdennis at redhat.com> wrote:
> What is the security threat with the IdP metadata? Is it because if it
>  was obtained insecurely it might be pointing to a rouge IdP?

Mainly that it would accept forged assertions, likely pushed from the attacker, with no need for any user to be involved.

> How does this lead to a breach of the campus data? Is it because the
>  rouge IdP acquired valid campus credentials and then used those 
> credentials to access campus data?

No, anybody can phish users much more easily than this, I'm talking about the fact that most cloud vendors with bad metadata practice are housing our data, not theirs, so an IdP that can impersonate users to access a vendor application is likely exposing the IdP's data, not the SP's data.

-- Scott




More information about the users mailing list