Impact of Reduced TLS Certificate Lifetimes on CA-Signed SAML Certificates

Peter Schober peter.schober at univie.ac.at
Thu May 22 16:26:24 UTC 2025


Peter Schober via users <users at shibboleth.net> [2025-05-22 17:57 CEST]:
> Wei Dai via users <users at shibboleth.net> [2025-05-20 18:56 CEST]:
> > While most of our customers use self-signed SAML certificates, some
> > have policies that require common CA-signed certificates for both
> > SAML IdPs and SPs.
> 
> With common SAML 2.0 WebSSO usage there is no TLS involved (for the
> SAML part, which is fully independent from the subject's web browser
> connecting via TLS to both the SP and the IDP web servers when
> mediating the exchange of SSO protocol messages.)
> So those pushing such policies would be well served by the adoption of
> published standards instead:
> https://wiki.oasis-open.org/security/SAML2MetadataIOP

Putting this differently: As the operator of an identity federation
with manual processes for entity registration/changes I will certainly
not re-register changed entities every couple of weeks only because
the deployers of such systems misunderstood the applicable trust
model(s). Nor will I be offering interfaces/tooling to make Doing The
Wrong Thing™ easier/more scalable for those deployers.

I've long had little sympathy for those of my fellow federation
operators that force frequent certificate (and often enough, by
ignorance or more misunderstanding from either those federation
operators or their respective members: private key) changes unto their
members/entities for no good reason (i.e., no relevant changes in the
percieved security of either the technologies or keys involved).

While I'm not getting my hopes up that the pain of following
inappropriate rules meant for other trust models (WebPKIX) will get
such federations to stop enforcing such policies it *will* have
operational consequences on how we work together in this area.

-peter


More information about the users mailing list