Re: [saml-dev] Same certificate for https and SAML signing

From
Vasu Y <>
Date
2014-03-13T04:50:15+00:00
ID
Thread
Re: [saml-dev] Same certificate for https and SAML signing
Hi All,

 Thanks for your valuable inputs.

I will use different keys for signing and encryption; will check with prospective customers if they are Okay with self-signed certs.

Questions on CA-signed certs:

1)
 Are there any specific issues/drawbacks when using CA-signed certificates apart from renewing?

2) Can someone throw light into "CA-signed certificates can lead to configurations that mistakenly establish trust based on the certificate signer." (Ref: https://spaces.internet2.edu/display/InCFederation/X.509+Certificates+in+Metadata#X.509CertificatesinMetadata-Background).

 

Thanks,

Vasu

  
 
 
    From: "Cantor, Scott" <>
 To: Tom Scavo
 <>; "Lucas, Mike" <> 
Cc: SAML Developers <>; "" <> 
 Sent: Tuesday, 11 March 2014 12:31 AM
 Subject: Re: [saml-dev] Same certificate for https and SAML signing
  
 

On 3/10/14, 2:36 PM, "Tom Scavo" <> wrote:
>>If you're referring to the SAML spec, it has nothing to say about this>issue. The companion spec that Peter pointed is one approach but there>is a small fraction of Federations worldwide (that I know of,
 anyway)>that employ a model based on CA-signed certificates in metadata.
As long as it's exactly one, controlled, CA, that's relatively safe.Otherwise it's simply asking to get hacked, because without namingconstraints and/or control over the issuance, you have no control overwhat's being issued and what the relationship is between a SAML name and asubject DN. There is nothing in SAML to do this, and there is no standardway of expressing the right rules in SAML metadata (though there arenon-standard ways).In short, a good number of SAML systems in the world have literally noidea what they're doing and are operating unsafely. That is probablyunsurprising since you could s/SAML/anything in that sentence and beaccurate.-- Scott---------------------------------------------------------------------To unsubscribe, e-mail:  additional commands, e-mail: