Notice from Adobe about IdP SHA-1 certificates

Cantor, Scott cantor.2 at osu.edu
Tue Jul 21 12:36:41 UTC 2020


On 7/21/20, 8:21 AM, "users on behalf of Peter Schober" <users-bounces at shibboleth.net on behalf of peter.schober at univie.ac.at> wrote:

>    So contrary to how this reads (also) to me, are people here saying
>    this is about their own SP certificate, that in fact they are changing
>    their SP certificate?!

They changed out their entire implementation from Okta to something else. When they notified us of that change, they did it under the cover of a very similar sounding email that referenced SHA-1 and all sorts of nonsense that made no sense until I poked into it, and I concluded they must have meant the old Okta instance was using a SHA-1 cert and the new SP didn't.

But other people continue to claim that this also or instead is in fact talking about the IdP. Since I didn't have a SHA-1 cert at any point in my use of Adobe's Okta SP, I can't say for sure.

But I sure as heck wouldn't take it at face value. I play chicken in a lot of these cases. If I think something might break, but probably won't, I often wait until it does and then deal with it before I rush to make a change to my system that has major ramifications. I just stage enough of the change to head it off if I have to fix it on short notice.

>    If not, are people actually considering to change their IDP key pair
>   (or adding another, one only for use with that vendor) based solely on
>    the nonsensical[1] request of a vendor to change the digest algorithm
>    on a (very likely) self-signed certificate?

No comment.

>    And even if Adobe (with either SP implementation, I hear ther are two:
>    one okta.com and another one?) absolutely refused to accept SAML
>    assertions/reponses that are signed with a certificate they detect as
>    using the sha1 digest algo -- why would I change my IDP certificate
>    when I could simply re-wrap that same key/modulus into another
>    self-signed certificate using the sha256 digest algo and upload that
>    re-wrapped certificate to their self-service consone?

That's what I've advised, obviously. But the answer is that people don't understand what that even means, so trying to push that way is only of limited value.

>    (Or is there hard evidence that they not only use the certificate on
>    record for sha1 digest checking but also that they require the
>    certificate embedded in the signed SAML assertion/response to
>    literally match the certificate they have on record -- not that simply
>    the signature can be validated?)

Until it's tested, I wouldn't know, but I've advised people that if you don't mean to change your actual key, I would probably at least consider keeping it the same because *some* number of SPs at least do in fact not care.

I don't know how much value that adds though. Even if Adobe allows it, the fact is most SPs that aren't metadata capable, do exact cert compares, yes. So you end up perhaps with an even messier state in some ways, not really knowing who's impacted or not.

>    I.e., there is nothing to gain from changing the digest algo of your
>    IDP signing certificate other than possibly to please people who have
>    no idea how this works or what any of this means, which certainly is
>    one road to hell.

" No idea how this works or what any of this means " describes 95% of the vendors I have, and I have upwards of 200 now.

-- Scott




More information about the users mailing list