<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=Windows-1252">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div style="font-family:Arial,Helvetica,sans-serif; font-size:9pt; color:rgb(0,0,0)">
Scott,</div>
<div style="font-family:Arial,Helvetica,sans-serif; font-size:9pt; color:rgb(0,0,0)">
<br>
</div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 9pt; color: rgb(0, 0, 0);">
<span style="background-color: rgb(255, 255, 128); font-size: 9pt;">"</span><font size="2"><span style="font-size: 9pt; background-color: rgb(255, 255, 128);">Signing requests is not only worthless, it's actively bad since it wastes CPU cycles. Siginng is needed
 for Logout requests, not for SSO.</span></font><span style="background-color: rgb(255, 255, 128); font-size: 9pt;">"</span></div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 9pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family:Arial,Helvetica,sans-serif; font-size:9pt; color:rgb(0,0,0)">
Perhaps I should state my question very simply -- in this case there is no signing certificate in the SP metadata. What is the "best practice" around requiring the SP certificate be included?
<br>
</div>
<div style="font-family:Arial,Helvetica,sans-serif; font-size:9pt; color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Arial,Helvetica,sans-serif; font-size:9pt; color:rgb(0,0,0)">
It's important that we clear this up on our end, before setting forth on the $ transactions.
<br>
</div>
<div style="font-family:Arial,Helvetica,sans-serif; font-size:9pt; color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Arial,Helvetica,sans-serif; font-size:9pt; color:rgb(0,0,0)">
Can you please either point to documentation for this or clarify SP signing certificate needs in the SAML security protocol?
<br>
</div>
<div style="font-family:Arial,Helvetica,sans-serif; font-size:9pt; color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Arial,Helvetica,sans-serif; font-size:9pt; color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Arial,Helvetica,sans-serif; font-size:9pt; color:rgb(0,0,0)">
<div class="confluence-information-macro confluence-information-macro-information conf-macro output-block">
<p class="title" style="margin-top: 0px; margin-bottom: 0px;"><i>Using a signing certificate</i></p>
<i><span class="aui-icon aui-icon-small aui-iconfont-info confluence-information-macro-icon"></span></i>
<div class="confluence-information-macro-body"><em>The term “signing certificate” is a misnomer. A signing certificate in metadata is actually used for signature verification, not signing. The private signing key is held securely by the signing party.</em></div>
</div>
<a href="https://wiki.shibboleth.net/confluence/display/CONCEPT/SAMLKeysAndCertificates#SAMLKeysAndCertificates-KeyDescriptorContent">https://wiki.shibboleth.net/confluence/display/CONCEPT/SAMLKeysAndCertificates#SAMLKeysAndCertificates-KeyDescriptorContent</a></div>
<div style="font-family:Arial,Helvetica,sans-serif; font-size:9pt; color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Arial,Helvetica,sans-serif; font-size:9pt; color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Arial,Helvetica,sans-serif; font-size:9pt; color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Arial,Helvetica,sans-serif; font-size:9pt; color:rgb(0,0,0)">
Thanks,<br>
Shweta<br>
</div>
<div style="font-family:Arial,Helvetica,sans-serif; font-size:9pt; color:rgb(0,0,0)">
<br>
</div>
<div id="appendonsend"></div>
<hr tabindex="-1" style="display:inline-block; width:98%">
<div id="divRplyFwdMsg" dir="ltr"><font style="font-size:11pt" face="Calibri, sans-serif" color="#000000"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Mak, Steve <makst@upenn.edu><br>
<b>Sent:</b> Friday, October 2, 2020 11:48 AM<br>
<b>To:</b> Shib Users <users@shibboleth.net><br>
<b>Subject:</b> [External] Re: Recommended or "Best" Practices for Shibboleth IdP?</font>
<div> </div>
</div>
<div class="BodyFragment"><font size="2"><span style="font-size:11pt">
<div class="PlainText">[CAUTION: External email. Do not click links or open attachments unless verified. Send all suspicious email as an attachment to spam@northcarolina.edu<mailto:spam@northcarolina.edu>]<br>
<br>
<br>
Don,<br>
<br>
> So how do you handle "making" a vendor change their metadata to include<br>
    a cert for signing and the validUntil setting<br>
<br>
With local SP metadata, we can add validUntil manually or enable/disable request signing.<br>
<br>
However, we only require request signing in a few scenarios. We generally encourage vendors to not use signing certs unless they have a good reason because FAR too many confuse SAML signing certs with TLS web certs, and insist that SAML signing certs need to
 be updated yearly.<br>
<br>
Generally the requirements for signing are that there must exist something in the SAML request that we want to make sure has not been modified. The primary feature we don't want to be modified is forceAuthn="true" if the sponsor wants to require ignore SSO.
 If the vendor can't do signing, we simply add a relying party override to turn on forceAuthn.<br>
<br>
The only other criteria for required SAML request signing would be wildcard ACS, but we don't have any in use nor have we permitted any SPs to do so yet, but we've planned to require request signing if we ever do allow it.<br>
<br>
- Steve<br>
<br>
<br>
--<br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg">
https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div>
</span></font></div>
</body>
</html>