<div dir="ltr">"They're wrong, starting with the fact that public keys and certificates don't create signatures, private keys do. You can't be uploading a certificate that does anything related to this problem unless you're also uploading the corresponding private key for it to use, which would be silly to do."<div><br></div><div>Actually, yes, they require the customer to generate the  RSA certificate public and private key with length 4096. The portal has me configure my IDP instance name, metadata (these seem normal), but then fill in what their entity ID is following their guidelines, upload a certificate and private key. From that, they have a button to generate the SP metadata. The signing certificate in that metadata is the one I've uploaded.</div><div><br></div><div>I will check with them on the signing of the AuthnRequests. <br clear="all"><div><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><p><span style="font-family:Arial,sans-serif;color:rgb(31,73,125)"><font size="1">Steve Herrera</font></span><span style="font-family:Arial,sans-serif;color:rgb(31,73,125)"><font size="1"><br>Information Security<br></font></span><span style="color:rgb(31,73,125);font-family:Arial,sans-serif;font-size:7.5pt">Bradley University<br></span><span style="color:rgb(31,73,125);font-family:Arial,sans-serif;font-size:7.5pt">Phone: 309 / 677-2336<br></span><span style="color:rgb(31,73,125);font-family:Arial,sans-serif;font-size:7.5pt">FAX: 309 / 677-3460<br></span><span style="font-size:7.5pt;font-family:Arial,sans-serif;color:rgb(31,73,125)">Email:  </span><u><span style="font-size:7.5pt;font-family:"Arial","sans-serif";color:blue"><a href="mailto:sherrera@fsmail.bradley.edu" target="_blank">sherrera@fsmail.bradley.edu</a></span></u></p></div></div></div></div><br></div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Wed, Oct 12, 2022 at 7:04 PM Cantor, Scott via users <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">>    The SP has a portal where I submit the certificate and generate it's<br>
> metadata. That's what I put in our IDP. There techs said that is the<br>
> certificate used to sign the request. <br>
<br>
They're wrong, starting with the fact that public keys and certificates don't create signatures, private keys do. You can't be uploading a certificate that does anything related to this problem unless you're also uploading the corresponding private key for it to use, which would be silly to do.<br>
<br>
You can upload *your* certificate, you can't upload theirs. It has to come from them.<br>
<br>
They also shouldn't be signing the AuthnRequests in the first place, that's not a useful thing to do.<br>
<br>
Then there's the fact that OpenSAML 3 is end-of-life and unsupported...<br>
<br>
-- Scott<br>
<br>
<br>
-- <br>
For Consortium Member technical support, see <a href="https://shibboleth.atlassian.net/wiki/x/ZYEpPw" rel="noreferrer" target="_blank">https://shibboleth.atlassian.net/wiki/x/ZYEpPw</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>