AWS Cognito

yingma yingma at ucla.edu
Mon Oct 15 16:27:08 EDT 2018


Hello Scott,

In the integration guide for AmazaonCognito here:
https://wiki.shibboleth.net/confluence/display/IDP30/AmazonCognito#AmazonCognito-ServiceProviderMetadata

there is no mention of the encryption/decryption of SAML response. In normal
SP registration case a sp-cert.pem is required from IDP, and that to my
understanding takes care encryption/decryption between IDP and SP. Will be
able to provide some insight on how this is handled in the case of Cognito
User Pool being the SP?

Our test Cognito User Pool publishes its public keys here in JSON Web Key
sets:
https://cognito-idp.us-west-2.amazonaws.com/us-west-2_ItdxO9s07/.well-known/jwks.json
AWS documentation tells us they are used for applications that use Cognito
User Pool to verify the user token. We assume the same public key(s) can be
used for encryption/decryption with Shibboleth IDP. Is this assumption
correct?

Any insight is greatly appreciated. Thanks!

Ying Ma
Application Development
UCLA External Affairs





--
Sent from: http://shibboleth.1660669.n2.nabble.com/Shibboleth-Users-f1660767.html


More information about the users mailing list