Service Provider not checking for certificate expiration
Ullfig, Roberto Alfredo
rullfig at uic.edu
Wed Jul 21 13:09:49 UTC 2021
OK, but I don't agree with the rationale behind this:
"Specifically, metadata obtained via an insecure transport should be both signed, and should expire, so that consumers are forced to refresh it often enough to limit the damage from compromised information."
The cat's out of the bag - it doesn't take very long to get access all the information. By the time you find out you should assume it's all been accessed and compromised. I don't see how a key rollover offers any protection whatsoever.
---
Roberto Ullfig - rullfig at uic.edu
Systems Administrator
Enterprise Applications & Services | Technology Solutions
University of Illinois - Chicago
________________________________
From: users <users-bounces at shibboleth.net> on behalf of Peter Schober <peter.schober at univie.ac.at>
Sent: Wednesday, July 21, 2021 7:49 AM
To: users at shibboleth.net <users at shibboleth.net>
Subject: Re: Service Provider not checking for certificate expiration
* Ullfig, Roberto Alfredo <rullfig at uic.edu> [2021-07-20 20:56]:
> We're running a service provider at version 3.2.3 and I noticed that
> if the assertions are signed with an expired certificate that the
> service provider will accept that - that doesn't seem
> right. Shouldn't the SP reject those assertions?
https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwiki.oasis-open.org%2Fsecurity%2FSAML2MetadataIOP&data=04%7C01%7Crullfig%40uic.edu%7Ce826c909e8aa4a7f0eef08d94c45f0c5%7Ce202cd477a564baa99e3e3b71a7c77dd%7C0%7C0%7C637624685838417056%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000&sdata=1bkky7tDJSUKgGUhRSIJ0d3lEZO2jRsNjQ47i4JSH6o%3D&reserved=0
Section 2.6.1 specifically but if you're asking that you'll want to
read at least the Introduction in full.
-peter
--
For Consortium Member technical support, see https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fx%2FZYEpPw&data=04%7C01%7Crullfig%40uic.edu%7Ce826c909e8aa4a7f0eef08d94c45f0c5%7Ce202cd477a564baa99e3e3b71a7c77dd%7C0%7C0%7C637624685838417056%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000&sdata=WBqIpUJ0y8sUXT%2F2B3AvL6eWDPZ8cQdJ%2BmgJ3UQwTcg%3D&reserved=0
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20210721/00af2987/attachment.htm>
More information about the users
mailing list