shibboleth-dev - RE: Shibboleth SP - Handling Encrypted Assertions
Subject: Shibboleth Developers
List archive
- From: <>
- To: <>
- Subject: RE: Shibboleth SP - Handling Encrypted Assertions
- Date: Tue, 11 Mar 2008 19:40:46 -0400
To add some additional
information. I was able to get the other IDP product to change such that it
included the x509 certificate used for encryption, and that solved the problem.
My question now becomes whether
this is considered 1)
A requirement Shibboleth
SPs place on IDPs to interoperate. 2)
Something the Shibboleth
SP can handle, but requires specific configuration to do (which I failed to
find). 3)
A Shibboleth SP bug
that will get attention at some point. 4)
An unimplemented Shibboleth
SP feature that is not likely to be implemented. Thanks, From: Brent Putman
[mailto:]
Does the Shibboleth SP have a requirement that Encrypted
Assertions must include a copy of the x509 certificate used to encrypt the
KeyInfo?
When the Shibboleth IDP encrypts an assertion, it includes a
copy of the SP’s x509 certificate, although I am unsure as to whether this is
strictly required (could it not be assumed?).
I am trying to test the Shibboleth SP with a different SAML
IDP product, and it is not including a copy of the SP’s encryption certificate,
and here is the sequence of messages I see in the logfile:
The logging differences make me think the issue is the lack
of including the X509Certificate, but I am not entirely sure if the problem is
related to the KeyInfo encryption algorithm (another point of variance, the
Shibboleth IDP uses rsa-oaep-mgf1p, but this product is using rsa-1_5 by
default, and I have not fully investigated changing this algorithm).
|
- Shibboleth SP - Handling Encrypted Assertions, Jeff.Krug, 03/11/2008
- Re: Shibboleth SP - Handling Encrypted Assertions, Brent Putman, 03/11/2008
- RE: Shibboleth SP - Handling Encrypted Assertions, Jeff.Krug, 03/11/2008
- Re: Shibboleth SP - Handling Encrypted Assertions, Scott Cantor, 03/11/2008
- Re: Shibboleth SP - Handling Encrypted Assertions, Scott Cantor, 03/12/2008
- RE: Shibboleth SP - Handling Encrypted Assertions, Jeff.Krug, 03/12/2008
- RE: Shibboleth SP - Handling Encrypted Assertions, Scott Cantor, 03/12/2008
- RE: Shibboleth SP - Handling Encrypted Assertions, Jeff.Krug, 03/12/2008
- Re: Shibboleth SP - Handling Encrypted Assertions, Scott Cantor, 03/12/2008
- Re: Shibboleth SP - Handling Encrypted Assertions, Brent Putman, 03/11/2008
Archive powered by MHonArc 2.6.16.