Hi All,
Thanks for your valuable inputs.
I will use different keys for signing and encryption; will check with prospective customers if they are Okay with self-signed certs.
Questions on CA-signed certs:
1)
Are there any specific issues/drawbacks when using CA-signed certificates apart from renewing?
2) Can someone throw light into "CA-signed certificates can lead to configurations that mistakenly establish trust based on the certificate signer." (Ref: https://spaces.internet2.edu/display/InCFederation/X.509+Certificates+in+Metadata#X.509CertificatesinMetadata-Background).
Thanks,
Vasu
From: "Cantor, Scott" <>
To: Tom Scavo
<>; "Lucas, Mike" <>
Cc: SAML Developers <>; "" <>
Sent: Tuesday, 11 March 2014 12:31 AM
Subject: Re: [saml-dev] Same certificate for https and SAML signing
On 3/10/14, 2:36 PM, "Tom Scavo" <> wrote:
>>If you're referring to the SAML spec, it has nothing to say about this>issue. The companion spec that Peter pointed is one approach but there>is a small fraction of Federations worldwide (that I know of,
anyway)>that employ a model based on CA-signed certificates in metadata.
As long as it's exactly one, controlled, CA, that's relatively safe.Otherwise it's simply asking to get hacked, because without namingconstraints and/or control over the issuance, you have no control overwhat's being issued and what the relationship is between a SAML name and asubject DN. There is nothing in SAML to do this, and there is no standardway of expressing the right rules in SAML metadata (though there arenon-standard ways).In short, a good number of SAML systems in the world have literally noidea what they're doing and are operating unsafely. That is probablyunsurprising since you could s/SAML/anything in that sentence and beaccurate.-- Scott---------------------------------------------------------------------To unsubscribe, e-mail: additional commands, e-mail: