[External] Re: Recommended or "Best" Practices for Shibboleth IdP?
Cantor, Scott
cantor.2 at osu.edu
Fri Oct 2 15:44:53 UTC 2020
On 10/2/20, 11:43 AM, "users on behalf of Shweta Kautia" <users-bounces at shibboleth.net on behalf of skautia at northcarolina.edu> wrote:
> I apologize -- i meant the vendor's own signing certificate for signed authentication requests.
Signing requests is not only worthless, it's actively bad since it wastes CPU cycles. Siginng is needed for Logout requests, not for SSO.
So them charging for something they shouldn't be doing is the best scam ever, but either somebody on your side made a mistake, or they're just trying to rob you.
-- Scott
More information about the users
mailing list