IdP Metadata certificate
Peter Schober
peter.schober at univie.ac.at
Wed Jul 8 09:04:21 UTC 2020
* Lohr, Donald - lohrda <lohrda at jmu.edu> [2020-07-08 01:21]:
> On occasion I get a non-InCommon SP vendor that reports that they
> can not use the cert in my IdP metadata because the cert has CRLF in
> it.
Well, the IETF standard that exists since 2015 and tries to accomodate
most existing previous practices is quite clear:
https://tools.ietf.org/html/rfc7468#section-2
"parsers SHOULD ignore whitespace and other non-
base64 characters and MUST handle different newline conventions."
> I do not understand why some of these vendor can and can not handle
> my IdP certificate, more over is it something I should even worry
> about addressing?
If you provide them with your IDP metadata bilaterally (instead of
having them pull it from InCommon's MDQ feed, which I'd recommend you
do instead) there's nothing stopping you from providing each vendor
with a customised version. That's also very silly, of course, ensuring
extra work for you in the future, should you ever need to change your
certificate.
-peter
More information about the users
mailing list