Question about relying-party-system.xml
Ullfig, Roberto Alfredo
rullfig at uic.edu
Wed Jun 30 19:20:06 UTC 2021
We looked at 45 days of login logs to get a list of entity ids and then ran a script to generate a spreadsheet with entity id and contact information extracted from the repositories. Then we manually searched for contacts for the remaining applications. There are over 240 active applications. ArcGIS looks only at the second cert and was the only one to break that we know of when we added the second cert. There's an InCommon document that mentions that EZProxy only looks at the first cert but I manually configure that one. I have only a handful of SPs to configure. We're making the change on a weekend but there's one SP (that we know of) whose SAML is maintained by the vendor and they don't work on weekends which is why I added support for a second cert - which won't expire until later in the week.
As for SHA1 vs SHA256 I was thinking in line of a very old application that doesn't know how to deal with a SHA256 signing certificate.
---
Roberto Ullfig - rullfig at uic.edu
Systems Administrator
Enterprise Applications & Services | Technology Solutions
University of Illinois - Chicago
________________________________
From: users <users-bounces at shibboleth.net> on behalf of Wessel, Keith <kwessel at illinois.edu>
Sent: Wednesday, June 30, 2021 2:01 PM
To: Shib Users <users at shibboleth.net>
Subject: RE: Question about relying-party-system.xml
We'll name ours, too: Ezri, maker of ArcGIS. I was impressed that they could consume a federation's metadata and use IdP discovery, and even validate the signature on the federation's aggregate. But when they got IdP metadata with multiple encryption certs, they didn't' try each cert to decrypt. To their credit, we reported the issue, and they have a developer actively working to fix it. Now if we could just convince some of these vendors that there are better options than creating your own SAML implementation...
Keith
-----Original Message-----
From: users <users-bounces at shibboleth.net> On Behalf Of Cantor, Scott
Sent: Wednesday, June 30, 2021 1:57 PM
To: Shib Users <users at shibboleth.net>
Subject: Re: Question about relying-party-system.xml
On 6/30/21, 2:48 PM, "users on behalf of Ullfig, Roberto Alfredo" <users-bounces at shibboleth.net on behalf of rullfig at uic.edu> wrote:
> Yes, understand all that. Service owners have long been notified -
> some applications have been tested with the new certificate, etc.
> We've even encountered an SP that broke when we added the second certificate to federated metadata.
I have also. I'll name them: Cornerstone.
> I think we've prepared as much as we could. Major applications should
> be fine - there might be a few that break though.
I have over 200 systems that are essentially either manually dealt with by me or manually by the vendor, so there's really no amount of preparing that would have done any good, I had to limit the change to the rest and deal with the others one by one over 9 months of time.
The only difference if I hadn't been changing the actual key is that if I had chosen to pull the plug all at once, there's a chance some number of the 200 would have worked, but I wouldn't even hazard a guess as to how many. I doubt it would have been more than half at best.
-- Scott
--
For Consortium Member technical support, see https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.com%2Fv3%2F__https%3A%2F%2Fwiki.shibboleth.net%2Fconfluence%2Fx%2FcoFAAg__%3B!!DZ3fjg!oViL6zBPYKbkS01a1ePMOSO1aoubv9j_X8Beg5Lbk26-_n2TKRuViWRh1M8NLQBYiA%24&data=04%7C01%7Crullfig%40uic.edu%7C9516525820fd4ee1f4c208d93bf9738c%7Ce202cd477a564baa99e3e3b71a7c77dd%7C0%7C0%7C637606764842461060%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=lXDX0%2BUlcbPQH%2Bb1%2FqTSrdCXBLbky1jnd2cuLwm25Pw%3D&reserved=0
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
--
For Consortium Member technical support, see https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwiki.shibboleth.net%2Fconfluence%2Fx%2FcoFAAg&data=04%7C01%7Crullfig%40uic.edu%7C9516525820fd4ee1f4c208d93bf9738c%7Ce202cd477a564baa99e3e3b71a7c77dd%7C0%7C0%7C637606764842461060%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=it7tdJTGS%2F72HCtlGoUhZaPGZds%2BMRKfK%2B3wt7uoVJ0%3D&reserved=0
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20210630/1b3fe22a/attachment.htm>
More information about the users
mailing list