Class 3 ssl certificate for SAML 2.0 federation
Peter Schober
peter.schober at univie.ac.at
Mon Oct 22 09:10:33 EDT 2018
* Kunal Shah <ks186033 at gmail.com> [2018-10-22 11:09]:
> For one of setups we are using SAML 2.0 federations. The CISO has
> made a mandate that for all certificate requirements we use Class 3
> certificates issued by third party CA.
Assuming you're talking about certificates solely used to secure SAML
protocol messages (NOT about TLS/HTTPS certificates): As such certs
typically won't ever be seen by an HTTP User Agent controlled by the
subject (with its own set of browser- and/or OS-vendor-supplied CA
certificates) using commercial TLS certs there serves no real purpose.
> I don't see any need for this. Especially when it is going to impact
> the budget of our project. We are planning to submit an exception
> request to the same. Can you please point me to some material that
> helps me building my case?
Try the SAML V2.0 Metadata Interoperability Profile:
https://wiki.oasis-open.org/security/SAML2MetadataIOP
Thousands[1] of organisations the world over are relying on this trust
model for secure, trustworhy federation.
-peter
[1] E.g. https://edugain.org/ has 5000+ entities these days.
More information about the users
mailing list