[External] Re: Recommended or "Best" Practices for Shibboleth IdP?

Cantor, Scott cantor.2 at osu.edu
Fri Oct 2 15:44:53 UTC 2020


On 10/2/20, 11:43 AM, "users on behalf of Shweta Kautia" <users-bounces at shibboleth.net on behalf of skautia at northcarolina.edu> wrote:

>    I apologize -- i meant the vendor's own signing certificate for signed authentication requests. 

Signing requests is not only worthless, it's actively bad since it wastes CPU cycles. Siginng is needed for Logout requests, not for SSO.

So them charging for something they shouldn't be doing is the best scam ever, but either somebody on your side made a mistake, or they're just trying to rob you.

-- Scott




More information about the users mailing list