<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
</head>
<body>
<div class="moz-cite-prefix">beacause they ask me for a
download/service URL for my IDP metadata</div>
<div class="moz-cite-prefix">you are right, I can probably create a
"fake" one on /var/www/html with apache serveur and remove all
encrypt references in those metadata<br>
</div>
<div class="moz-cite-prefix">but I am afraid that if their SP
refresh dynamically my IDP metadata and while echanging assertion
maybe the need to access/check <a class="moz-txt-link-freetext"
href="https://myidp.domain.fr/idp/shibboleth">
https://myidp.domain.fr/idp/shibboleth</a> ? <br>
</div>
<div class="moz-cite-prefix"><br>
</div>
<div class="moz-cite-prefix">So in there a way to completly remove
encrypt assertion from the IDP workflow and associated metadata ?
<br>
</div>
<div class="moz-cite-prefix"><br>
</div>
<div class="moz-cite-prefix">Thanks . <br>
</div>
<div class="moz-cite-prefix"><br>
</div>
<div class="moz-cite-prefix"><br>
</div>
<div class="moz-cite-prefix">Le 13/06/2020 à 00:25, Ray Bon a
écrit :<br>
</div>
<blockquote type="cite"
cite="mid:228cc1be8130e43b694f89709e11894710e264a8.camel@uvic.ca">
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
<div>Jehan,</div>
<div><br>
</div>
<div>What is preventing the vendor from editing their copy of your
metadata?</div>
<div><br>
</div>
<div>Ray</div>
<div><br>
</div>
<div>On Fri, 2020-06-12 at 23:28 +0200, Jehan Procaccia wrote:</div>
<blockquote type="cite" style="margin:0 0 0 .8ex; border-left:2px
#729fcf solid;padding-left:1ex">
<div style="font-size:8pt; color:#f58442 ; font-family:
sans-serif; font-style:normal; font-weight:bold; padding:.2em">
Notice: This message was sent from outside the University of
Victoria email system. Please be cautious with links and
sensitive information.
</div>
<br>
<div>
<p>Hello <br>
</p>
<p>from <a class="moz-txt-link-freetext"
href="https://wiki.shibboleth.net/confluence/display/IDP30/SecurityConfiguration"
moz-do-not-send="true">
https://wiki.shibboleth.net/confluence/display/IDP30/SecurityConfiguration</a>
I see that I can invalidate encryption for specific SP
/entityID :
<br>
</p>
<p><i><bean parent="SAML2.SSO" p:encryptAssertions="false"
/></i><br>
</p>
<p>I know it's dirty , but the Vendor I am trying to do SSO
with, not only ask for no encryption (only signing) , but
wants the metadataFile of our IDP to contain only the
signing certificat no occurence of :<br>
</p>
<p><i><KeyDescriptor use="encryption"></i></p>
<p>because it fails their integration tool to have 2
certificates in metadata<br>
</p>
<p>Is there a way in the configuration of the IDP to
completely invalidate encryption at the point to make it
desappear from Metadata ?
<br>
</p>
<p>I tried to comment in credentials.xml <i><br>
</i></p>
<p><i><util:list
id="shibboleth.DefaultEncryptionCredentials"></i><i><br>
</i><i> <bean
class="net.shibboleth.idp.profile.spring.factory.BasicX509CredentialFactoryBean"</i><i><br>
</i><i>
p:privateKeyResource="%{idp.encryption.key}"</i><i><br>
</i><i>
p:certificateResource="%{idp.encryption.cert}"</i><br>
</p>
<p>but still <i><KeyDescriptor use="encryption"></i>
appears in metadata at <a class="moz-txt-link-freetext"
href="https://myidp.domain.fr/idp/shibboleth"
moz-do-not-send="true">
https://myidp.domain.fr/idp/shibboleth</a></p>
<p>Or should I edit myself idp-metadata.xml and "blindly"
remove all the section:
<br>
</p>
<p><i> <KeyDescriptor use="encryption"></i><i><br>
</i><i> <ds:KeyInfo></i><i><br>
</i><i> <ds:X509Data></i><i><br>
</i><i> <ds:X509Certificate></i><i><br>
</i><i>MIIDNzCCAh+gAwIBAgIUQ1XYtG2d7w4EbppsM3JMNZNhjIYwDQYJKoZIhvcNAQEL</i><br>
</p>
<p>Thanks . <br>
</p>
<p><br>
</p>
</div>
</blockquote>
<div><span>
<pre>--
</pre>
<div>Ray Bon</div>
<div>Programmer Analyst</div>
<div>Development Services, University Systems</div>
<div>2507218831 | CLE 019 | <a href="mailto:rbon@uvic.ca"
moz-do-not-send="true">rbon@uvic.ca</a></div>
<div><br>
</div>
<div>I respectfully acknowledge that my place of work is
located within the ancestral, traditional and unceded
territory of the Songhees, Esquimalt and WSÁNEĆ Nations.</div>
</span></div>
<br>
<fieldset class="mimeAttachmentHeader"></fieldset>
</blockquote>
<p><br>
</p>
</body>
</html>