IdP and algorithm support extensions in SP metadata

Michael Grady mgrady at unicon.net
Fri Oct 13 21:16:50 UTC 2023


I won't go into the details about why this is desired, but is there any way to tell the IdP to *ignore* algorithm extensions in SP metadata, and to prioritize an entity attribute filter that is adding a securityConfig override to that SP entry?

There are SPs where the metadata is currently coming from the InCommon MDQ service, and their metadata includes a list of supported digest and signing algorithms. (SPs not registered by InCommon, because as far as I can tell, the InCommon Federation Manager does not provide a way to add that to SP metadata. But other federations such as the UK, SurfNet, etc.  do have SP metadata with those tags.) The IdP in questions has an ECDSA signiing cert as its default cert, but for a variety of reasons, the IdP signing cert registered in the InCommon metadata is an alternate RSA2048 cert. We were trying to tell the IdP to use that alternate cert for all InCommon-sourced SP metadata, but if that SP metadata says that it supports ECDSA, that is "trumping" the attempted securityConfig override to NOT use that ECDSA cert.

Is there any way to stop the IdP from doing that, short of bringing that metadata in locally and changing it directly?

--
Michael A. Grady
IAM Architect, Unicon, Inc.





More information about the users mailing list