[External] Re: Recommended or "Best" Practices for Shibboleth IdP?
Shweta Kautia
skautia at northcarolina.edu
Fri Oct 2 15:03:04 UTC 2020
And I'll just add to that scenario.. we are currently dealing with a vendor that is charging $ to add a signing certificate for existing SSO implementations. No support for encrypted assertions either.
Has anyone mandated it after the fact and how does one justify spending $ for it?
thanks,
Shweta
________________________________
From: users <users-bounces at shibboleth.net> on behalf of Donald Lohr <lohrda at jmu.edu>
Sent: Friday, October 2, 2020 10:36 AM
To: users at shibboleth.net <users at shibboleth.net>
Subject: [External] Re: Recommended or "Best" Practices for Shibboleth IdP?
[CAUTION: External email. Do not click links or open attachments unless verified. Send all suspicious email as an attachment to spam at northcarolina.edu<mailto:spam at northcarolina.edu>]
So how do you handle "making" a vendor change their metadata to include
a cert for signing and the validUntil setting, especially when your
Senior management is dictating that a badly designed application be
added to your Shibboleth service?
Thanks,
Don
On 9/30/20 7:06 PM, Cantor, Scott wrote:
> The lack of validUntil on the order of weeks, or a signature under a separate key, is instantly disqualifying for any source of metadata because there is no viable trust model without them.
--
D o n a l d L o h r
I n f o r m a t i o n S y s t e m s
J a m e s M a d i s o n U n i v e r s i t y
5 4 0 . 5 6 8 . 3 7 3 0
--
For Consortium Member technical support, see https://wiki.shibboleth.net/confluence/x/coFAAg
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20201002/1505875f/attachment.htm>
More information about the users
mailing list