Question around multiple keys in SAML Metadata
Paul B. Henson
henson at acm.org
Mon May 4 22:40:24 UTC 2026
On Mon, May 04, 2026 at 05:25:14PM -0500, James Epp via users wrote:
> I've come into disagreement with a vendor
[...]
> I was all but certain SAML-compliance required SPs
Hehehehe... Vendors and standards compliance mix like oil and water ;).
Section 2.6.1 "Key Processing" is pretty clear:
"Each key expressed by a <md:KeyDescriptor> element within a particular
role MUST be treated as valid when processing messages or assertions in
the context of that role. Specifically, any signatures or transport
communications (e.g., TLS/SSL sessions) verifiable with a signing key
MUST be treated as valid, and any encryption keys found MAY be used to
encrypt messages or assertions (or encryption keys) intended for the
containing entity."
The standard allows multiple keys to be included in metadata, the
standard says each key MUST be treated as valid.
Your vendor doesn't have a leg to stand on, although sadly that will
likely have no impact on their desire or ability to fix their broken
implementation <sigh>.
More information about the users
mailing list