Service Provider not checking for certificate expiration
Nate Klingenstein
ndk at signet.id
Tue Jul 20 19:01:16 UTC 2021
Roberto,
Shibboleth has and probably always will regard certificates as just a convenient bag for public keys. The rest of the certificate is basically disregarded, and trust is bootstrapped entirely through metadata instead.
Take care,
Nate.
--------
Signet, Inc.
The Art of Access ®
https://www.signet.id
-----Original message-----
From: Ullfig, Roberto Alfredo
Sent: Tuesday, July 20 2021, 6:56 pm
To: Shib Users
Subject: Service Provider not checking for certificate expiration
We're running a service provider at version 3.2.3 and I noticed that if the assertions are signed with an expired certificate that the service provider will accept that - that doesn't seem right. Shouldn't the SP reject those assertions?
---
Roberto Ullfig - rullfig at uic.edu
Systems Administrator
Enterprise Applications & Services | Technology Solutions
University of Illinois - Chicago
--
For Consortium Member technical support, see https://shibboleth.atlassian.net/wiki/x/ZYEpPw
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list