Skip to Content.

edugain-discuss - Re: [eduGAIN-discuss] reference for expired certificate warning

edugain-discuss AT lists.geant.org

Subject: An open discussion list for topics related to the eduGAIN interfederation service.

List archive


Re: [eduGAIN-discuss] reference for expired certificate warning


Chronological Thread 
  • From: Nick Roy <nroy AT internet2.edu>
  • To: Leif Johansson <leifj AT sunet.se>
  • Cc: "edugain-discuss AT lists.geant.org" <edugain-discuss AT lists.geant.org>
  • Subject: Re: [eduGAIN-discuss] reference for expired certificate warning
  • Date: Wed, 20 Nov 2019 17:41:30 +0000
  • Accept-language: en-US
  • Arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=internet2.edu; dmarc=pass action=none header.from=internet2.edu; dkim=pass header.d=internet2.edu; arc=none
  • Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=QPKrZBLmaWgmeO4/Um0fCmY2tnIAGPNOVFNgipBwfcE=; b=QX6UG5dvQBV4/akdJlTgSvOqtrn2jXJ6rh+niARfyqbkSs/4Wdl8zvommfOzMQvaCII2jpTi1j0lbBzI8VhHJKVNqZpF501wxDAX5MU5DPywwual3SyXgOyXi8GzSz6HFN7ubDgiyD/iTtMkrxkZlleWZa6t57xxJ2t5xhm29sXnxySxbVvulxcrFW+E2r6GVqUaSpEBy/r3r/mIDz/thhUVj5nTl405iI28hLXg9E1J+PRtmsY/hrhYKtb9hqE1XjOSkucgofmIYLu4AVUw3OvcML4lPZBhj9UP2Ss2DEGUT5hj22wBanSxWbwW/yG4ervy9kpMdQHqDrkAWNNlLw==
  • Arc-seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=j241kNQJEnHM/Mjrpbw/g8lRcO+CYnHY9XAKgulMPXwz0H0fEezvzdNfYjyQRYGF2NDKstxS6gDj5y5P+1N8Um3j5CJbHJLHmlkLgr7MGv3s3ZW9rNJYP1yaG8W23waQEdBDc2ZG84o5r289iHSgFyx4LqzO8O6X20ZlkPJXYkkRbIqfuB91bdMt5TBzG5NyUba//D9zjijnsKBnAoWYH/uAdGp1iIi6xiZHpnyyOul97arSMIf7C254AvKuGQhh/9/As+zoSDupyoJp39QuK+ZrUahgkmLIP4DWwNH2M2E9+uOQkb+akcHXwe7+jp0tX55ZFFHhAgn6EvDwNPzVGg==
  • Authentication-results: spf=none (sender IP is ) smtp.mailfrom=nroy AT internet2.edu;

Pamela Dingle was always receptive to the needs of this community when she
worked at Ping. In fact, she was instrumental, along with Hans Zandbelt, in
getting Ping Identity to a much better place than it was w/r/t our mode of
operation.

The problem with ADFS is that it's not a problem that is limited to those who
choose to sniff that sock. If you can't support key rollover, you cause
problems for all of your federating partners. If you don't know what you're
doing, you end up causing outages, wasting the time of your peers in the
federation, and of federation operators.

Nick

On 20 Nov 2019, at 3:34, Leif Johansson wrote:

> On 2019-11-20 09:50, Peter Schober wrote:
>> * Nick Roy <nroy AT internet2.edu> [2019-11-20 00:03]:
>>> Perhaps counterproductively adding to my rant below: ADFS is
>>> terrible, but works just well enough to lull people into the belief
>>> that it won’t screw everything up, as it invariably does, down the
>>> road. I spend at least 80% of my direct-end-user-contact time
>>> coaching people with ADFS problems. ADFS *should not be used* in the
>>> context of R&E federations, nor should other similar software. This
>>> is a real problem that I don’t know how to address in our context,
>>> but the problem is getting worse every day.
>>
>> Thank you for your very clear words in this regard.
>>
>> Maybe this should be made known more widely? Open to ideas how that
>> would work. A REFEDS blog post? A disclaimer message to be relayed by
>> (Full Mesh) federations?
>> I'll start by quoting your post above in our documentation.
>>
>> At this time we only have a single MS-ADFS entity registered, so my
>> communication has been pretty clear and seemingly was effective so
>> far. That one entity could end up being used a lot more, though,
>> through services proxied behind its SP-side...
>>
>> -peter
>>
>
> While I tend to agree the pain is mostly localized to those that
> choose to sniff this particular sock. The organizations who run
> ADFS do that for reasons that will not be influenced by what
> REFEDS say.
>
> We may be able to get MSFT to improve things... I have had some
> chats with their new head of identity (or whatever the title is)
> Pamela Dingle who at least make the right noices. I know this is
> not the first time somebody said this too.
>
> Possibly a statement from REFEDS if wielded in a smart way may
> serve to make things a bit more concrete.
>
> Cheers Leif

Attachment: signature.asc
Description: OpenPGP digital signature




Archive powered by MHonArc 2.6.19.

Top of Page