Real impact of turning off SimpleSigning
Kim, Allan
jak009 at ucsd.edu
Fri Mar 14 21:14:45 UTC 2025
Per the updated SECADV, ‘there is no workaround within the SP configuration other than to remove the SimpleSigning security policy rule from the security-policy.xml file entirely.” We are seeing about 15% of incoming AuthnRequests at our IdP using simple signature, but we haven’t yet found any instances of outgoing messages using it. My admittedly very limited testing so far shows no obvious impact for our predominant use case – Shibboleth SP paired with a Shibboleth IdP. Of course when we turned off XMLSignature as a test, we promptly received an “Unable to establish security of incoming assertion” error message 😊
Has anyone identified a potential problem with turning off SimpleSigning in a typical Shib SP / Shib IdP use case? Thanks in advance for sharing your expertise!
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20250314/3d749d28/attachment.htm>
More information about the users
mailing list