SAML Token?

Cantor, Scott cantor.2 at osu.edu
Thu Apr 26 09:10:58 EDT 2018


> On Thu, 2018-04-26 at 11:08:59 +0200, Peter Schober wrote:
> > […]
> >And of course provided you're willing to forgo encryption with the SP
> >(as there's no key).
> 
> Isn't that pretty much standard SaaS SAML (best?)practice these days? ; P
> *evil laughter*

Not as much as I tend to exaggerate. I actually only had about a dozen or so that had it turned off when the time came to start testing all of them. A couple were self-inflicted (bad key practices so I had avoided turning it on).

A lot of the time they have the support and just never bothered to enable it, it's just a matter of asking.

An interesting observation is that we're now past the original generation of IT staff who just assume they know how keys are supposed to be handled and would try to change it every year and into a new generation that wouldn't even think of doing anything not self-signed unless you were to point it out to them.

-- Scott



More information about the users mailing list