Service Provider not checking for certificate expiration

Nate Klingenstein ndk at signet.id
Tue Jul 20 19:01:16 UTC 2021


Roberto,

Shibboleth has and probably always will regard certificates as just a convenient bag for public keys.  The rest of the certificate is basically disregarded, and trust is bootstrapped entirely through metadata instead.

Take care,
Nate.

--------
Signet, Inc.
The Art of Access ®

https://www.signet.id

-----Original message-----
From: Ullfig, Roberto Alfredo
Sent: Tuesday, July 20 2021, 6:56 pm
To: Shib Users
Subject: Service Provider not checking for certificate expiration

We're running a service provider at version 3.2.3 and I noticed that if the assertions are signed with an expired certificate that the service provider will accept that - that doesn't seem right. Shouldn't the SP reject those assertions?

---

Roberto Ullfig - rullfig at uic.edu
Systems Administrator
Enterprise Applications & Services | Technology Solutions
University of Illinois - Chicago

--

For Consortium Member technical support, see https://shibboleth.atlassian.net/wiki/x/ZYEpPw

To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net




More information about the users mailing list