Conversation
according to SAML2 spec http://docs.oasis-open.org/security/saml/v2.0/saml-profiles-2.0-os.pdf lines 1276-1277 logout messages must be signed in case of front channel. see also spring-attic#145
|
@strehle Please sign the Contributor License Agreement! Click here to manually synchronize the status of this Pull Request. See the FAQ for frequently asked questions. |
|
@strehle Thank you for signing the Contributor License Agreement! |
|
Hi @fhanik , |
|
Hi @strehle , A change like this would break existing implementations for a branch that is only released when critical security fixes are needed. Can the UAA not simply call |
|
Hi @fhanik I would have set this in UAA if possible, but due to issue The workaround we did, we patched the class in spring-security-saml and this fixed the issue and does not break any existing scenarios because the signature is part of the standard and IDPs handle an existing signature. The issue is not visible if you only have a 1 : 1 relation , IDP : SP, but if there are several SPs conected to an IDP the signature in the logout is a MUST to logout all SPs. So if you fix issue #145 then this would also solve this here. |
according to
SAML2 spec http://docs.oasis-open.org/security/saml/v2.0/saml-profiles-2.0-os.pdf lines 1276-1277 logout messages must be signed in case of front channel.
see also #145