<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 9pt; color: rgb(0, 0, 0);">
And I'll just add to that scenario.. we are currently dealing with a vendor that is charging $ to add a signing certificate for existing SSO implementations. No support for encrypted assertions either.
<br>
</div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 9pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 9pt; color: rgb(0, 0, 0);">
Has anyone mandated it after the fact and how does one justify spending $ for it?
<br>
</div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 9pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 9pt; color: rgb(0, 0, 0);">
thanks, <br>
</div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 9pt; color: rgb(0, 0, 0);">
Shweta<br>
</div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 9pt; color: rgb(0, 0, 0);">
<br>
</div>
<br>
<div id="appendonsend"></div>
<hr style="display:inline-block;width:98%" tabindex="-1">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" style="font-size:11pt" color="#000000"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Donald Lohr <lohrda@jmu.edu><br>
<b>Sent:</b> Friday, October 2, 2020 10:36 AM<br>
<b>To:</b> users@shibboleth.net <users@shibboleth.net><br>
<b>Subject:</b> [External] Re: Recommended or "Best" Practices for Shibboleth IdP?</font>
<div> </div>
</div>
<div class="BodyFragment"><font size="2"><span style="font-size:11pt;">
<div class="PlainText">[CAUTION: External email. Do not click links or open attachments unless verified. Send all suspicious email as an attachment to spam@northcarolina.edu<mailto:spam@northcarolina.edu>]<br>
<br>
<br>
So how do you handle "making" a vendor change their metadata to include<br>
a cert for signing and the validUntil setting, especially when your<br>
Senior management is dictating that a badly designed application be<br>
added to your Shibboleth service?<br>
<br>
<br>
Thanks,<br>
Don<br>
<br>
On 9/30/20 7:06 PM, Cantor, Scott wrote:<br>
> The lack of validUntil on the order of weeks, or a signature under a separate key, is instantly disqualifying for any source of metadata because there is no viable trust model without them.<br>
<br>
--<br>
D o n a l d L o h r<br>
I n f o r m a t i o n S y s t e m s<br>
J a m e s M a d i s o n U n i v e r s i t y<br>
5 4 0 . 5 6 8 . 3 7 3 0<br>
<br>
--<br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg">
https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div>
</span></font></div>
</body>
</html>