Skip to content

Question: Configuration to verify that signed response originates from IDP #592

@Rob1080

Description

@Rob1080

Code Version

pysaml 4.5

Expected Behavior

When the idp changes their certificate, and we we have the old cert configured in the metadata, I'd expect a failure to occur.

Current Behavior

The response passes and the signed responses is confirmed to be valid, I'm assuming from the cert that's included in the response.

Question

Am I missing something in my configuration or should it by default be checking that the cert in the metadata is the same as the cert in response?

Thanks
Rob

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions