Service Provider not checking for certificate expiration
Peter Schober
peter.schober at univie.ac.at
Wed Jul 21 12:49:01 UTC 2021
* Ullfig, Roberto Alfredo <rullfig at uic.edu> [2021-07-20 20:56]:
> We're running a service provider at version 3.2.3 and I noticed that
> if the assertions are signed with an expired certificate that the
> service provider will accept that - that doesn't seem
> right. Shouldn't the SP reject those assertions?
https://wiki.oasis-open.org/security/SAML2MetadataIOP
Section 2.6.1 specifically but if you're asking that you'll want to
read at least the Introduction in full.
-peter
More information about the users
mailing list