<html dir="ltr">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body style="text-align:left; direction:ltr;">
<div>Jehan,</div>
<div><br>
</div>
<div>What is preventing the vendor from editing their copy of your metadata?</div>
<div><br>
</div>
<div>Ray</div>
<div><br>
</div>
<div>On Fri, 2020-06-12 at 23:28 +0200, Jehan Procaccia wrote:</div>
<blockquote type="cite" style="margin:0 0 0 .8ex; border-left:2px #729fcf solid;padding-left:1ex">
<div style="font-size:8pt; color:#f58442 ; font-family: sans-serif; font-style:normal; font-weight:bold; padding:.2em">
Notice: This message was sent from outside the University of Victoria email system. Please be cautious with links and sensitive information.
</div>
<br>
<div>
<p>Hello <br>
</p>
<p>from <a class="moz-txt-link-freetext" href="https://wiki.shibboleth.net/confluence/display/IDP30/SecurityConfiguration" moz-do-not-send="true">
https://wiki.shibboleth.net/confluence/display/IDP30/SecurityConfiguration</a> I see that I can invalidate encryption for specific SP /entityID :
<br>
</p>
<p><i><bean parent="SAML2.SSO" p:encryptAssertions="false" /></i><br>
</p>
<p>I know it's dirty , but the Vendor I am trying to do SSO with, not only ask for no encryption (only signing) , but wants the metadataFile of our IDP to contain only the signing certificat no occurence of :<br>
</p>
<p><i><KeyDescriptor use="encryption"></i></p>
<p>because it fails their integration tool to have 2 certificates in metadata<br>
</p>
<p>Is there a way in the configuration of the IDP  to completely invalidate encryption at the point to make it desappear from Metadata ?
<br>
</p>
<p>I tried to comment in credentials.xml <i><br>
</i></p>
<p><i><util:list id="shibboleth.DefaultEncryptionCredentials"></i><i><br>
</i><i>        <bean class="net.shibboleth.idp.profile.spring.factory.BasicX509CredentialFactoryBean"</i><i><br>
</i><i>            p:privateKeyResource="%{idp.encryption.key}"</i><i><br>
</i><i>            p:certificateResource="%{idp.encryption.cert}"</i><br>
</p>
<p>but still <i><KeyDescriptor use="encryption"></i> appears in metadata at  <a class="moz-txt-link-freetext" href="https://myidp.domain.fr/idp/shibboleth" moz-do-not-send="true">
https://myidp.domain.fr/idp/shibboleth</a></p>
<p>Or should I edit myself idp-metadata.xml and "blindly" remove all the section:
<br>
</p>
<p><i>       <KeyDescriptor use="encryption"></i><i><br>
</i><i>            <ds:KeyInfo></i><i><br>
</i><i>                    <ds:X509Data></i><i><br>
</i><i>                        <ds:X509Certificate></i><i><br>
</i><i>MIIDNzCCAh+gAwIBAgIUQ1XYtG2d7w4EbppsM3JMNZNhjIYwDQYJKoZIhvcNAQEL</i><br>
</p>
<p>Thanks . <br>
</p>
<p><br>
</p>
</div>
</blockquote>
<div><span>
<pre>-- <br></pre>
<div>Ray Bon</div>
<div>Programmer Analyst</div>
<div>Development Services, University Systems</div>
<div>2507218831 | CLE 019 | <a href="mailto:rbon@uvic.ca">rbon@uvic.ca</a></div>
<div><br>
</div>
<div>I respectfully acknowledge that my place of work is located within the ancestral, traditional and unceded territory of the Songhees, Esquimalt and WSÁNEĆ Nations.</div>
</span></div>
</body>
</html>