Skip to Content.
Sympa Menu

mace-opensaml-users - RE: [OpenSAML] How to validate signing certificate of the SAML token in the relaying party?

Subject: OpenSAML user discussion

List archive

RE: [OpenSAML] How to validate signing certificate of the SAML token in the relaying party?


Chronological Thread 
  • From: "Cantor, Scott E." <>
  • To: "" <>
  • Subject: RE: [OpenSAML] How to validate signing certificate of the SAML token in the relaying party?
  • Date: Thu, 28 Apr 2011 16:44:08 +0000
  • Accept-language: en-US

> Thanks for all your responses. I am a Service Provider. The application that
> we provide to our clients is not sensitive, so I am not planning to make a
> complex validation.

Until they change the app or your code gets copied around as an example or
approach for some other app.

> My identity provider is Microsoft ADFS2.0 and my
> application is receiving SAML2.0 tokens from ADFS and I don't use any other
> third party product. I exported token signing certificate from ADFS and
> placed it in my application(SP). The singing certificate has an expiration
> date of one year. My worry is after one year what happens? I will keep work
> as normal or something will break?

That's up to you. And what happens if and when they change it?

You need to read what I provided as background. It's not optional if you're
implementing SAML (or anything else involving keys for trust management).

-- Scott




Archive powered by MHonArc 2.6.16.

Top of Page