AWS Cognito

Cantor, Scott cantor.2 at osu.edu
Mon Oct 15 16:30:55 EDT 2018


> there is no mention of the encryption/decryption of SAML response.

I'm pretty sure it outright states they don't support encryption, which is the case.

> In normal
> SP registration case a sp-cert.pem is required from IDP and that to my
> understanding takes care encryption/decryption between IDP and SP. Will be
> able to provide some insight on how this is handled in the case of Cognito User
> Pool being the SP?

It isn't, they don't support encryption.

> AWS documentation tells us they are used for applications that use Cognito
> User Pool to verify the user token. We assume the same public key(s) can be
> used for encryption/decryption with Shibboleth IDP. Is this assumption correct?

No, it's not.

-- Scott



More information about the users mailing list