IdP assertions encryption issue
Tom Scavo
trscavo at gmail.com
Wed Jan 31 12:56:43 EST 2018
On Wed, Jan 31, 2018 at 12:27 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:
>
> The recent security bug demonstrates that XML Encryption, which I would have generally agreed was mostly a "nice to have" is in fact utterly essential to protect against lots of attacks, known and unknown.
>
> If you want to avoid the back channel, you need encryption, full stop. Otherwise you should follow the CAS/OIDC school of thought that POST is unsafe and use callbacks.
>
> I'm moving strongly to the "I won't do business with an SP that doesn't have a key" school of thought...
Let me see if I understand what you're saying...if an IdP can not (or
will not) encrypt the response, it should send use artifact. Is that
what you are recommending?
Tom
More information about the users
mailing list