Service Provider not checking for certificate expiration

Peter Schober peter.schober at univie.ac.at
Wed Jul 21 12:49:01 UTC 2021


* Ullfig, Roberto Alfredo <rullfig at uic.edu> [2021-07-20 20:56]:
> We're running a service provider at version 3.2.3 and I noticed that
> if the assertions are signed with an expired certificate that the
> service provider will accept that - that doesn't seem
> right. Shouldn't the SP reject those assertions?

https://wiki.oasis-open.org/security/SAML2MetadataIOP

Section 2.6.1 specifically but if you're asking that you'll want to
read at least the Introduction in full.

-peter


More information about the users mailing list