<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
  </head>
  <body>
    <div class="moz-cite-prefix">beacause they ask me for a
      download/service  URL for my IDP metadata</div>
    <div class="moz-cite-prefix">you are right, I can probably create a
      "fake" one on /var/www/html with apache serveur and remove all
      encrypt references in those metadata<br>
    </div>
    <div class="moz-cite-prefix">but I am afraid that if their SP
      refresh dynamically my IDP metadata and while echanging assertion
      maybe the need to access/check <a class="moz-txt-link-freetext"
        href="https://myidp.domain.fr/idp/shibboleth">
        https://myidp.domain.fr/idp/shibboleth</a>  ? <br>
    </div>
    <div class="moz-cite-prefix"><br>
    </div>
    <div class="moz-cite-prefix">So in there a way to completly remove
      encrypt assertion from the IDP workflow and associated metadata ?
      <br>
    </div>
    <div class="moz-cite-prefix"><br>
    </div>
    <div class="moz-cite-prefix">Thanks . <br>
    </div>
    <div class="moz-cite-prefix"><br>
    </div>
    <div class="moz-cite-prefix"><br>
    </div>
    <div class="moz-cite-prefix">Le 13/06/2020 à 00:25, Ray Bon a
      écrit :<br>
    </div>
    <blockquote type="cite"
      cite="mid:228cc1be8130e43b694f89709e11894710e264a8.camel@uvic.ca">
      <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
      <div>Jehan,</div>
      <div><br>
      </div>
      <div>What is preventing the vendor from editing their copy of your
        metadata?</div>
      <div><br>
      </div>
      <div>Ray</div>
      <div><br>
      </div>
      <div>On Fri, 2020-06-12 at 23:28 +0200, Jehan Procaccia wrote:</div>
      <blockquote type="cite" style="margin:0 0 0 .8ex; border-left:2px
        #729fcf solid;padding-left:1ex">
        <div style="font-size:8pt; color:#f58442 ; font-family:
          sans-serif; font-style:normal; font-weight:bold; padding:.2em">
          Notice: This message was sent from outside the University of
          Victoria email system. Please be cautious with links and
          sensitive information.
        </div>
        <br>
        <div>
          <p>Hello <br>
          </p>
          <p>from <a class="moz-txt-link-freetext"
href="https://wiki.shibboleth.net/confluence/display/IDP30/SecurityConfiguration"
              moz-do-not-send="true">
https://wiki.shibboleth.net/confluence/display/IDP30/SecurityConfiguration</a>
            I see that I can invalidate encryption for specific SP
            /entityID :
            <br>
          </p>
          <p><i><bean parent="SAML2.SSO" p:encryptAssertions="false"
              /></i><br>
          </p>
          <p>I know it's dirty , but the Vendor I am trying to do SSO
            with, not only ask for no encryption (only signing) , but
            wants the metadataFile of our IDP to contain only the
            signing certificat no occurence of :<br>
          </p>
          <p><i><KeyDescriptor use="encryption"></i></p>
          <p>because it fails their integration tool to have 2
            certificates in metadata<br>
          </p>
          <p>Is there a way in the configuration of the IDP  to
            completely invalidate encryption at the point to make it
            desappear from Metadata ?
            <br>
          </p>
          <p>I tried to comment in credentials.xml <i><br>
            </i></p>
          <p><i><util:list
              id="shibboleth.DefaultEncryptionCredentials"></i><i><br>
            </i><i>        <bean
class="net.shibboleth.idp.profile.spring.factory.BasicX509CredentialFactoryBean"</i><i><br>
            </i><i>           
              p:privateKeyResource="%{idp.encryption.key}"</i><i><br>
            </i><i>           
              p:certificateResource="%{idp.encryption.cert}"</i><br>
          </p>
          <p>but still <i><KeyDescriptor use="encryption"></i>
            appears in metadata at  <a class="moz-txt-link-freetext"
              href="https://myidp.domain.fr/idp/shibboleth"
              moz-do-not-send="true">
              https://myidp.domain.fr/idp/shibboleth</a></p>
          <p>Or should I edit myself idp-metadata.xml and "blindly"
            remove all the section:
            <br>
          </p>
          <p><i>       <KeyDescriptor use="encryption"></i><i><br>
            </i><i>            <ds:KeyInfo></i><i><br>
            </i><i>                    <ds:X509Data></i><i><br>
            </i><i>                        <ds:X509Certificate></i><i><br>
            </i><i>MIIDNzCCAh+gAwIBAgIUQ1XYtG2d7w4EbppsM3JMNZNhjIYwDQYJKoZIhvcNAQEL</i><br>
          </p>
          <p>Thanks . <br>
          </p>
          <p><br>
          </p>
        </div>
      </blockquote>
      <div><span>
          <pre>-- 
</pre>
          <div>Ray Bon</div>
          <div>Programmer Analyst</div>
          <div>Development Services, University Systems</div>
          <div>2507218831 | CLE 019 | <a href="mailto:rbon@uvic.ca"
              moz-do-not-send="true">rbon@uvic.ca</a></div>
          <div><br>
          </div>
          <div>I respectfully acknowledge that my place of work is
            located within the ancestral, traditional and unceded
            territory of the Songhees, Esquimalt and WSÁNEĆ Nations.</div>
        </span></div>
      <br>
      <fieldset class="mimeAttachmentHeader"></fieldset>
    </blockquote>
    <p><br>
    </p>
  </body>
</html>