<div dir="ltr"><div class="gmail_default" style="font-family:arial,helvetica,sans-serif"> </div><div class="gmail_extra">
<br><div class="gmail_quote">On Thu, Feb 25, 2016 at 1:49 PM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="">> In an SP config, when specifying a DS URL for a SessionInitiator type SAMLDS<br>
> or when specifying discoveryURL for an SSO, why is a certificate not used to<br>
> validate the respective URLs?<br>
<br>
</span>The SP isn't the one accessing it. And it's set by you, so if the value isn't a good one, you've just caused whatever bad outcome you're worried about.<br>
<br>
The browser of course "validates" it if it's an https URL, but that of course is theater.<br>
<span class=""><br>
> Seems like a hole to me. Is it assumed the target URL is running under a<br>
> known SP?<br>
<br>
</span>Which target URL are we talking about?<br>
<span class="HOEnZb"><font color="#888888"><br>
-- Scott<br></font></span></blockquote><div><br></div><div><div class="gmail_default" style="font-family:arial,helvetica,sans-serif;display:inline">​The URL of the DS, for example, the Shibboleth EDS.​</div> </div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="HOEnZb"><font color="#888888">
</font></span><div class="HOEnZb"><div class="h5"><br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br></div></div>