<div dir="ltr">Thank you Rod, as you mentioned that we don't have "<span style="font-size:12.8000001907349px">defaultSigningCredential" and we have the profiles with signAssertions="never" signResponses="never".</span><div><span style="font-size:12.8000001907349px"><br></span></div><div><span style="font-size:12.8000001907349px">Please look into the following our defaultRelyingPatry configuration, it hink which is not secure:</span></div><div><span style="font-size:12.8000001907349px"><br></span></div><div><span style="font-size:12.8000001907349px"><br></span></div><div><span style="font-size:12.8000001907349px"><br></span></div><div><div style><span style="font-size:12.8000001907349px"><DefaultRelyingParty provider="<a href="https://idp.example.org/idp/shibboleth">https://idp.example.org/idp/shibboleth</a>"></span></div><div style><span style="font-size:12.8000001907349px"><span class="" style="white-space:pre">        </span> </span></div><div style><span style="font-size:12.8000001907349px"><span class="" style="white-space:pre">        </span> <!-- defaultSigningCredentialRef="IdPCredential"--></span></div><div style><span style="font-size:12.8000001907349px"> </span></div><div style><span style="font-size:12.8000001907349px"> <ProfileConfiguration xsi:type="saml:ShibbolethSSOProfile"</span></div><div style><span style="font-size:12.8000001907349px"> includeAttributeStatement="false"</span></div><div style><span style="font-size:12.8000001907349px"> assertionLifetime="1800000"</span></div><div style><span style="font-size:12.8000001907349px"> signResponses="never" </span></div><div style><span style="font-size:12.8000001907349px"> signAssertions="never" /></span></div><div style><span style="font-size:12.8000001907349px"><br></span></div><div style><span style="font-size:12.8000001907349px"> <ProfileConfiguration xsi:type="saml:SAML1AttributeQueryProfile"</span></div><div style><span style="font-size:12.8000001907349px"> assertionLifetime="1800000" </span></div><div style><span style="font-size:12.8000001907349px"><span class="" style="white-space:pre">                                                        </span> signResponses="never" <span class="" style="white-space:pre">                                                        </span> </span></div><div style><span style="font-size:12.8000001907349px"> signAssertions="never" /></span></div><div style><span style="font-size:12.8000001907349px"><br></span></div><div style><span style="font-size:12.8000001907349px"> <ProfileConfiguration xsi:type="saml:SAML1ArtifactResolutionProfile"</span></div><div style><span style="font-size:12.8000001907349px"> signResponses="never"<span class="" style="white-space:pre">                                                        </span> </span></div><div style><span style="font-size:12.8000001907349px"> signAssertions="never" /></span></div><div style><span style="font-size:12.8000001907349px"><br></span></div><div style><span style="font-size:12.8000001907349px"> <ProfileConfiguration xsi:type="saml:SAML2SSOProfile"</span></div><div style><span style="font-size:12.8000001907349px"> includeAttributeStatement="true"</span></div><div style><span style="font-size:12.8000001907349px"> assertionLifetime="1800000"</span></div><div style><span style="font-size:12.8000001907349px"> assertionProxyCount="0"</span></div><div style><span style="font-size:12.8000001907349px"> signResponses="never"</span></div><div style><span style="font-size:12.8000001907349px"> signAssertions="never"</span></div><div style><span style="font-size:12.8000001907349px"><span class="" style="white-space:pre">                         </span>encryptAssertions="never"</span></div><div style><span style="font-size:12.8000001907349px"> encryptNameIds="never" /></span></div><div style><span style="font-size:12.8000001907349px"><br></span></div><div style><span style="font-size:12.8000001907349px"> <ProfileConfiguration xsi:type="saml:SAML2AttributeQueryProfile"</span></div><div style><span style="font-size:12.8000001907349px"> assertionLifetime="1800000"</span></div><div style><span style="font-size:12.8000001907349px"> assertionProxyCount="0"</span></div><div style><span style="font-size:12.8000001907349px"> signResponses="never"</span></div><div style><span style="font-size:12.8000001907349px"> signAssertions="never"</span></div><div style><span style="font-size:12.8000001907349px"> encryptAssertions="never"</span></div><div style><span style="font-size:12.8000001907349px"> encryptNameIds="never" /></span></div><div style><span style="font-size:12.8000001907349px"><br></span></div><div style><span style="font-size:12.8000001907349px"> <ProfileConfiguration xsi:type="saml:SAML2ArtifactResolutionProfile"</span></div><div style><span style="font-size:12.8000001907349px"> signResponses="never"</span></div><div style><span style="font-size:12.8000001907349px"> signAssertions="never"</span></div><div style><span style="font-size:12.8000001907349px"> encryptAssertions="never"</span></div><div style><span style="font-size:12.8000001907349px"> encryptNameIds="never"/></span></div><div style><span style="font-size:12.8000001907349px"> </DefaultRelyingParty></span></div><div class="gmail_extra"><br></div><div class="gmail_extra">In the above code we are not using 'signing' and 'encryption' for saml transmission. Even though we are not using any of the 'signing' and 'encryption' seen above, we use <X:509 certificate>in idp-meatadata.xml.</div><div class="gmail_extra">1) What might be the purpose of <X:509-Certificate> in the idp-metadata.xml?</div><div class="gmail_extra"><br></div><div class="gmail_extra"> 2) Are we done improper configuration or Is it because of using own SP not from Shibboleth?</div><div class="gmail_extra"><br></div><div class="gmail_extra">Thanks for your valuable time.</div><div class="gmail_extra"><br></div><div class="gmail_extra"><br><div class="gmail_quote">On Mon, Mar 30, 2015 at 1:10 PM, Rod Widdowson <span dir="ltr"><<a href="mailto:rdw@steadingsoftware.com" target="_blank">rdw@steadingsoftware.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-color:rgb(204,204,204);border-left-style:solid;padding-left:1ex"><span class="">> We have the lines in relying-party.xml which are commented out like below.<br>
><br>
> <!-- security:Credential id="IdPCredential" xsi:type="security:X509Filesystem" --<br>
> ><br>
> <!-- security:PrivateKey>d:\IdP/credentials/idp.key</security:PrivateKey--><br>
> <!-- security:Certificate>d:\IdP/credentials/idp.crt</security:Certificate--><br>
> <!-- /security:Credential--><br>
<br>
</span>So you (probably) have *no* *signing* on your IdP. I'd assume that your <DefaultRelyingParty> does *not* does not have a defaultSigningCredential and all the profiles specify<br>
signAssertions="never" and signResponses="never".<br>
<br>
This is weird, and almost certainly insecure against many threat models, but quite possible.<br>
<br>
If any of these are not true then you need to find the security:Credential with the id the same as the value for defaultSigningCredential (on DefaultRelyingParty) or signingCredentialRef (on the <ProfileConfiguration>)<br>
<br>
Note that this does not preclude your IdP from encrypting (because it uses the SP certificate)<br>
<span class=""><br>
> It seems we are not using the above lines in our configuration. but in "idp-<br>
> metadata.xml" we have the certificate copied like below:<br>
> <IDPSSODescriptor protocolSupportEnumeration="urn:mace:shibboleth:1.0<br>
> urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:2.0:protocol"><br>
<br>
</span>That is quite feasible. The metadata is generated during the installation from information that is gathered then and it is *NEVER UPDATED*.<br>
<span class=""><font color="#888888"><br>
Rod<br>
</font></span><div class=""><div class="h5"><br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br></div></div></div>