Impact of Reduced TLS Certificate Lifetimes on CA-Signed SAML Certificates

Peter Schober peter.schober at univie.ac.at
Thu May 22 15:57:23 UTC 2025


Wei Dai via users <users at shibboleth.net> [2025-05-20 18:56 CEST]:
> While most of our customers use self-signed SAML certificates, some
> have policies that require common CA-signed certificates for both
> SAML IdPs and SPs.

With common SAML 2.0 WebSSO usage there is no TLS involved (for the
SAML part, which is fully independent from the subject's web browser
connecting via TLS to both the SP and the IDP web servers when
mediating the exchange of SSO protocol messages.)
So those pushing such policies would be well served by the adoption of
published standards instead:
https://wiki.oasis-open.org/security/SAML2MetadataIOP

Best regards,
-peter


More information about the users mailing list