<html><body>
        <div dir="ltr">Additional note of caution:</div><div dir="ltr">While the IdP does not check validity of the certs in metadata for expiry, the SP in question *might* expire their metadata in concert with expiry of the certs.</div><div dir="ltr">The IdP does honor SP metadata expiration if specified in EntityDescriptor.</div><div dir="ltr"><br></div><div dir="ltr">David St. Pierre Bantz<br><br>
    <div class="gmail_quote">
        <div dir="ltr" class="gmail_attr">On 3Dec, 2020 at 06:19:20, Mark Cairney <<a href="mailto:Mark.Cairney@ed.ac.uk">Mark.Cairney@ed.ac.uk</a>> wrote:<br></div>
        <blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
            <div>
    <p>Thanks,</p>
    <p>That's what I thought was the case but thought it best to check
      first.</p>
    <p>For info the appropriate paragraph from the standard is:</p>
    <p>"</p>
    <p class="Standard"><span style="font-family:"Arial",sans-serif">In the case of
        an X.509 certificate, there are no requirements as to the
        content of the
        certificate apart from the requirement that it contain the
        appropriate public
        key. Specifically, the certificate may be expired, not yet
        valid, carry
        critical or non-critical extensions or usage flags, and contain
        any subject or
        issuer. The use of the certificate structure is merely a matter
        of notational
        convenience to communicate a key and has no semantics in this
        profile apart
        from that. However, it is RECOMMENDED that certificates be
        unexpired.</span></p>
    <p class="Standard"><span style="font-family:"Arial",sans-serif">"</span></p>
    <p class="Standard"><span style="font-family:"Arial",sans-serif">I'll feed this
        back but also point out that other IdP implementations may
        behave differently.</span></p>
    <p class="Standard"><span style="font-family:"Arial",sans-serif">Kind regards,</span></p>
    <p class="Standard"><span style="font-family:"Arial",sans-serif">Mark<br>
      </span></p>
    <div class="moz-cite-prefix">On 03/12/2020 14:16, Cantor, Scott
      wrote:<br>
    </div>
    <blockquote type="cite" cite="mid:DM6PR01MB4076867B9C848541D7F581DBD0F20@DM6PR01MB4076.prod.exchangelabs.com">
      <blockquote type="cite">
        <pre class="moz-quote-pre">Does the IdP do any validity checking of certificates or does it simply ignore the
expiry data?
</pre>
      </blockquote>
      <pre class="moz-quote-pre">No. What we do is exactly what's defined in the standard.

<a class="moz-txt-link-freetext" href="https://wiki.oasis-open.org/security/SAML2MetadataIOP">https://wiki.oasis-open.org/security/SAML2MetadataIOP</a>

Unless you only care about Shibboleth IdPs, that's not going to matter much.

-- Scott

</pre>
    </blockquote>
  




    The University of Edinburgh is a charitable body, registered in<br>Scotland, with registration number SC005336.<br>




    -- <br>For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</div>
        </blockquote>
    </div>
</div>
    
</body></html>