[EXT] Re: encrypt assertion with static AES key

Paul B. Henson henson at cpp.edu
Fri Apr 11 00:34:39 UTC 2025


> From: Brent Putman
> Subject: [EXT] Re: encrypt assertion with static AES key
>
> I'll leave to your judgement whether you actually want to attempt to acquiesce
> to this vendor's highly atypical requirement. :-)

Heh. My main goal here was to be factually correct in my choice between "you're an idiot, the spec doesn't allow that", "you're an idiot, that's technically part of the spec but impossible to actually implement in practice", or "while I suppose we could do that it's ridiculously stupid and you're an idiot to want to" ;).

I appreciate you and Scott taking the time to review the technical details, it's always nice to learn something new even in this questionable context :).

We will probably just disable encryption for this provider. It seems updating their metadata to properly tag the certificate included as for signing only is going to take them a month or two to sort out 8-/, but given they aren't in a federation it's not like I'm consuming it directly, I just have a local copy I can edit myself.

Thanks again…


More information about the users mailing list