PingOne SSO cloud integrations
Cantor, Scott
cantor.2 at osu.edu
Tue Jan 28 12:35:18 EST 2020
On 1/28/20, 12:01 PM, "users on behalf of Schwendner, Joanne" <users-bounces at shibboleth.net on behalf of joanne_schwendner at brown.edu> wrote:
> I am wondering if anyone else on this list has done SAML integrations with users of "PingOne SSO for SaaS Apps" --
> PingFederate's cloud-based, multi-tenant product.
I have plenty of Ping SPs, I don't know how to distinguish which ones would be using this thing, unless they're recognizable. I have not noticed duplicate keys but probably would not notice that easily, though I would know if I'd been given a duplicate entityID.
> I'd be interested in comments about this.
Well, given the mass adoption of proxies across the research space, one might say what's good for the goose...
Proxies are proxies. They are what they are, and they'll be used to the limits of what people allow them to be used for.
I would probably raise a red flag about it if I caught a case like this with a duplicate key, but I can't say that I'm certain what the outcome would be. We regularly tolerate blatantly insecure practices by vendors, some mind-boggling. I can't imagine this being the straw that would break any camels for us, noting that we don't even require encryption to begin with.
-- Scott
More information about the users
mailing list