ExplicitKey TrustEngine KeyName mismatch issue
Scott Cantor
scott at restingparrotsoftware.com
Mon Feb 2 13:22:17 UTC 2026
The key name checking was implemented primarily to deal with encryption keys to allow an IdP to signal which key was used when there are multiple keys available. It has some unfortunate side effects and it isn't really something one can work around when it affects the signature check because those credentials aren't in the SP's own configuration.
> As per the information I received from the people in charge, both the federation metadata and the IdP key name cannot be adjusted from their ends.
Won't, not cannot. Then you're going to have to handle the metadata yourself, I guess. Or you can stand up for yourself and force them to change it, because they sure as hell can. They just don't want to.
> From the documentation and the information I got from the person who runs the IdP with which I run into this issue, it is my understanding that the key name should be irrelevant for the ExplicitTrust trust engine.
It's not that clear cut, but even if it were, that code isn't changing decades after it was built, so it's moot.
-- Scott
More information about the users
mailing list