<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40"><head><META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=us-ascii"><meta name=Generator content="Microsoft Word 12 (filtered medium)"><style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:Tahoma;
        panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
p.MsoAcetate, li.MsoAcetate, div.MsoAcetate
        {mso-style-priority:99;
        mso-style-link:"Balloon Text Char";
        margin:0in;
        margin-bottom:.0001pt;
        font-size:8.0pt;
        font-family:"Tahoma","sans-serif";}
span.BalloonTextChar
        {mso-style-name:"Balloon Text Char";
        mso-style-priority:99;
        mso-style-link:"Balloon Text";
        font-family:"Tahoma","sans-serif";}
span.EmailStyle19
        {mso-style-type:personal;
        font-family:"Calibri","sans-serif";
        color:windowtext;}
span.EmailStyle20
        {mso-style-type:personal;
        font-family:"Calibri","sans-serif";
        color:#1F497D;}
span.EmailStyle21
        {mso-style-type:personal-reply;
        font-family:"Calibri","sans-serif";
        color:#1F497D;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-size:10.0pt;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]--></head><body lang=EN-US link=blue vlink=purple><div class=WordSection1><p class=MsoNormal><span style='color:#1F497D'>Hi Paul,<o:p></o:p></span></p><p class=MsoNormal><span style='color:#1F497D'><o:p>&nbsp;</o:p></span></p><p class=MsoNormal><span style='color:#1F497D'>We have an option to encrypt the Assertion, so the IDP needs our cert.&nbsp; The SP side just needs the private key to decrypt the assertions?&nbsp; No need to import the Cert on the SP side?&nbsp; Or will the SP not decrypt without both the Cert and the private key?<o:p></o:p></span></p><p class=MsoNormal><span style='color:#1F497D'><o:p>&nbsp;</o:p></span></p><p class=MsoNormal><span style='color:#1F497D'>Thanks,<o:p></o:p></span></p><p class=MsoNormal><span style='color:#1F497D'><o:p>&nbsp;</o:p></span></p><p class=MsoNormal><span style='color:#1F497D'>Carl<o:p></o:p></span></p><p class=MsoNormal><span style='color:#1F497D'><o:p>&nbsp;</o:p></span></p><div><div style='border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in'><p class=MsoNormal><b><span style='font-size:10.0pt;font-family:"Tahoma","sans-serif"'>From:</span></b><span style='font-size:10.0pt;font-family:"Tahoma","sans-serif"'> users-bounces@shibboleth.net [mailto:users-bounces@shibboleth.net] <b>On Behalf Of </b>Paul Hethmon<br><b>Sent:</b> Tuesday, February 12, 2013 11:25 AM<br><b>To:</b> Shib Users<br><b>Subject:</b> Re: question about Service Provider Cert<o:p></o:p></span></p></div></div><p class=MsoNormal><o:p>&nbsp;</o:p></p><div><p class=MsoNormal><span style='font-size:10.5pt;color:black'>Sounds right. You just furnish them with the signed public key, let them figure out how to store it.<o:p></o:p></span></p></div><div><p class=MsoNormal><span style='font-size:10.5pt;color:black'><o:p>&nbsp;</o:p></span></p></div><div><p class=MsoNormal><span style='font-size:10.5pt;color:black'>Since you're doing IdP initiated SSO, are you encrypting attributes then with the certs? Otherwise, I don't see a need to even have a cert on the SP side.<o:p></o:p></span></p></div><div><p class=MsoNormal><span style='font-size:10.5pt;color:black'><o:p>&nbsp;</o:p></span></p></div><div><p class=MsoNormal><span style='font-size:10.5pt;color:black'>Paul<o:p></o:p></span></p></div><div><p class=MsoNormal><span style='font-size:10.5pt;color:black'><o:p>&nbsp;</o:p></span></p></div><div style='border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in'><p class=MsoNormal><b><span style='color:black'>From: </span></b><span style='color:black'>Carl Buxbaum &lt;<a href="mailto:cbuxbaum@tradestonesoftware.com">cbuxbaum@tradestonesoftware.com</a>&gt;<br><b>Reply-To: </b>Shibboleth Users &lt;<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>&gt;<br><b>Date: </b>Tuesday, February 12, 2013 11:05 AM<br><b>To: </b>Shibboleth Users &lt;<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>&gt;<br><b>Subject: </b>RE: question about Service Provider Cert<o:p></o:p></span></p></div><div><p class=MsoNormal><span style='font-size:10.5pt;color:black'><o:p>&nbsp;</o:p></span></p></div><div><div><p class=MsoNormal><span style='color:#1F497D'>Thanks for the reply.&nbsp; Yes, I am referring to the former, and although we are doing IDP initiated SSO and there will be no communication from the SP back to the IDP, the customer insists that the cert be signed.&nbsp; So the signed cert gets reimported back into the keystore and placed in the metadata (or whatever they use to configure their IDP).&nbsp; And I gather that, if the &nbsp;public/private key is created outside of keytool, then the customer will be able to download the private key from the CA and import that into our keystore as well.&nbsp; I forgot to mention that we are using the OpenSAML 2.0 API, and not the Shibolleth SP.</span><span style='color:black'><o:p></o:p></span></p><p class=MsoNormal><span style='color:#1F497D'>&nbsp;</span><span style='color:black'><o:p></o:p></span></p><p class=MsoNormal><span style='color:#1F497D'>Thanks,</span><span style='color:black'><o:p></o:p></span></p><p class=MsoNormal><span style='color:#1F497D'>&nbsp;</span><span style='color:black'><o:p></o:p></span></p><p class=MsoNormal><span style='color:#1F497D'>Carl</span><span style='color:black'><o:p></o:p></span></p><p class=MsoNormal><span style='color:#1F497D'>&nbsp;</span><span style='color:black'><o:p></o:p></span></p><div><div style='border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in'><p class=MsoNormal><b><span style='font-size:10.0pt;font-family:"Tahoma","sans-serif";color:black'>From:</span></b><span style='font-size:10.0pt;font-family:"Tahoma","sans-serif";color:black'> <a href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a> [<a href="mailto:users-bounces@shibboleth.net">mailto:users-bounces@shibboleth.net</a>] <b>On Behalf Of </b>Paul Hethmon<br><b>Sent:</b> Monday, February 11, 2013 4:04 PM<br><b>To:</b> Shib Users<br><b>Subject:</b> Re: question about Service Provider Cert</span><span style='color:black'><o:p></o:p></span></p></div></div><p class=MsoNormal><span style='color:black'>&nbsp;<o:p></o:p></span></p><div><p class=MsoNormal><span style='font-size:10.5pt;color:black'>Carl,</span><span style='color:black'><o:p></o:p></span></p></div><div><p class=MsoNormal><span style='font-size:10.5pt;color:black'>&nbsp;</span><span style='color:black'><o:p></o:p></span></p></div><div><p class=MsoNormal><span style='font-size:10.5pt;color:black'>Are you referring to the public/private key used by Shibboleth SP to sign authentication requests? Or are you referring to an SSL certificate used to provide confidentiality to your web server? If the later, then Shibboleth does not care. The transport layer security is before Shib gets involved. You can secure it as you would any SSL protected site.</span><span style='color:black'><o:p></o:p></span></p></div><div><p class=MsoNormal><span style='font-size:10.5pt;color:black'>&nbsp;</span><span style='color:black'><o:p></o:p></span></p></div><div><p class=MsoNormal><span style='font-size:10.5pt;color:black'>If the former, you'll need to create your private key, then a certificate signing request, and then have a commercial CA sign it. Then you will have the private key and signed public key to use in your Shibboleth configuration. Note that Shibboleth does not care about SAML signing keys being &quot;signed&quot; by a commercial CA. Also note it adds no additional trust or security to do so. Trust is established by you furnishing your public key to the IdP by an out of band process and them trusting it was you that furnished it. Having a commercial CA sign that key adds no value. It does however cause you to keep up with its expiration date year in and year out.</span><span style='color:black'><o:p></o:p></span></p></div><div><p class=MsoNormal><span style='font-size:10.5pt;color:black'>&nbsp;</span><span style='color:black'><o:p></o:p></span></p></div><div><p class=MsoNormal><span style='font-size:10.5pt;color:black'>Paul</span><span style='color:black'><o:p></o:p></span></p></div><div><p class=MsoNormal><span style='font-size:10.5pt;color:black'>&nbsp;</span><span style='color:black'><o:p></o:p></span></p></div><div style='border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in'><p class=MsoNormal><b><span style='color:black'>From: </span></b><span style='color:black'>Carl Buxbaum &lt;<a href="mailto:cbuxbaum@tradestonesoftware.com">cbuxbaum@tradestonesoftware.com</a>&gt;<br><b>Reply-To: </b>Shibboleth Users &lt;<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>&gt;<br><b>Date: </b>Monday, February 11, 2013 3:31 PM<br><b>To: </b>Shibboleth Users &lt;<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>&gt;<br><b>Subject: </b>question about Service Provider Cert<o:p></o:p></span></p></div><div><p class=MsoNormal><span style='font-size:10.5pt;color:black'>&nbsp;</span><span style='color:black'><o:p></o:p></span></p></div><div><div><p class=MsoNormal><span style='color:black'>Hi,<o:p></o:p></span></p><p class=MsoNormal><span style='color:black'>&nbsp;<o:p></o:p></span></p><p class=MsoNormal><span style='color:black'>I am trying to get a handle on the certificate installation for a Service Provider implementation.&nbsp; I successfully developed and tested a SP &nbsp;IDP initiated SSO implementation using a self signed certificate against the Shibboleth IDP, but the customer requires a CA issued cert.&nbsp; According to the documentation of the CA, they talk about generating a cert request, and then importing the entire certificate chain into my SP keystore.&nbsp; Since I already have the private key in my keystore, do I really need to import anything else after running keytool &#8211;genkey? Do I need to import the resulting cert into the IDP?&nbsp; And the rest of the cert chain? Or do I just take the resulting cert and place it in the metadata for the Identity Provider? &nbsp;The Identity Provider they are using is PingFederate.<o:p></o:p></span></p><p class=MsoNormal><span style='color:black'>&nbsp;<o:p></o:p></span></p><p class=MsoNormal><span style='color:black'>Thanks for the help.<o:p></o:p></span></p><p class=MsoNormal><span style='color:black'>&nbsp;<o:p></o:p></span></p><p class=MsoNormal><b><span style='font-size:10.0pt;color:navy'>Carl&nbsp; Buxbaum</span></b><span style='color:black'><o:p></o:p></span></p><p class=MsoNormal><span style='font-size:10.0pt;color:navy'>Software Architect</span><span style='color:black'><o:p></o:p></span></p><p class=MsoNormal><span style='font-size:10.0pt;color:navy'>TradeStone Software</span><span style='color:black'><o:p></o:p></span></p><p class=MsoNormal><span style='font-size:10.0pt;color:navy'>17 Rogers St. Suite 2; Gloucester, MA 01930</span><span style='color:black'><o:p></o:p></span></p><p class=MsoNormal><span style='font-size:10.0pt;color:#002060'>P: 978-515-5128 </span><span style='font-size:10.0pt;color:navy'>F : 978-281-0673</span><span style='color:black'><o:p></o:p></span></p><p class=MsoNormal><span style='color:black'><a href="http://www.tradestonesoftware.com"><span style='font-size:10.0pt'>www.tradestonesoftware.com</span></a><o:p></o:p></span></p><p class=MsoNormal><span style='color:black'>&nbsp;<o:p></o:p></span></p><p class=MsoNormal><span style='font-size:10.5pt;color:black'><br>DISCLAIMER: <br>E-mails and attachments from TradeStone Software, Inc. are confidential.<br>If you are not the intended recipient, please notify the sender immediately by<br>replying to the e-mail, and then delete it without making copies or using it<br>in any way. No representation is made that this email or any attachments are<br>free of viruses. Virus scanning is recommended and is the responsibility of<br>the recipient.</span><span style='color:black'><o:p></o:p></span></p></div></div><p class=MsoNormal><span style='font-size:10.5pt;color:black'><br>DISCLAIMER: <br>E-mails and attachments from TradeStone Software, Inc. are confidential.<br>If you are not the intended recipient, please notify the sender immediately by<br>replying to the e-mail, and then delete it without making copies or using it<br>in any way. No representation is made that this email or any attachments are<br>free of viruses. Virus scanning is recommended and is the responsibility of<br>the recipient.<o:p></o:p></span></p></div></div></div><br clear="both">
DISCLAIMER: <BR>
E-mails and attachments from TradeStone Software, Inc. are confidential.<BR>
If you are not the intended recipient, please notify the sender immediately by<BR>
replying to the e-mail, and then delete it without making copies or using it<BR>
in any way. No representation is made that this email or any attachments are<BR>
free of viruses. Virus scanning is recommended and is the responsibility of<BR>
the recipient.<BR>
</body></html>