[EXTERN] Re: Shibboleth Identity Provider Security Advisory [13 May 2026]
Bernd Oberknapp
bo at ub.uni-freiburg.de
Thu May 14 16:23:43 UTC 2026
On 5/14/26 17:20, Peter Schober via users wrote:
>
>> That leads directly to the point that it's not meant for public
>> consumption, it's a system artifact of a service designed to be used
>> by the federations. If they're happy with it, fine. But by exposing
>> it to clients, I think they kind of have an obligation to do things
>> sensibly or tell people that they don't intend to cater to that use
>> case.
>
> I think there probably were (are?) a few offenders among the eduGAIN
> participant federations who did not understand that it's plain wrong
> to point their members to the eduGAIN MDS ("trust is always local", as
> leifj often said, here meaning: there's no reason any IDP or SP
> deployer should trust the eduGAIN MDS metadata or signing key).
> If this were up to me I'd long have restricted access to that resource
> to only the participant federations who need to process it.
> Doing that now doesn't of course address the issue.
Just to clarify, our IdP uses the eduGAIN SP metadata file provided by the
DFN-AAI (not the one provided by eduGAIN), but that has the same issue.
Best regards,
Bernd
--
Bernd Oberknapp
Gesamtleitung ReDI
Albert-Ludwigs-Universität Freiburg
Universitätsbibliothek
Platz der Universität 2 | Postfach 1629
D-79098 Freiburg | D-79016 Freiburg
Telefon: +49 761 203-3852
E-Mail: bo at ub.uni-freiburg.de
Internet: www.ub.uni-freiburg.de
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 6302 bytes
Desc: S/MIME Cryptographic Signature
URL: <http://shibboleth.net/pipermail/users/attachments/20260514/eea38d07/attachment.p7s>
More information about the users
mailing list