Skip to content

When detecting Silver SAML you should check for "KeyDescription" events #1

@denniskniep

Description

@denniskniep

When detecting Silver SAML it might be not enough to monitor for changes to PreferredTokenSigningKeyThumbprint
Because this event "only" signals the activation of an already uploaded certificate.

But the event that describes a change of the certificates is KeyDescription. In this event the old certs and new certs are listed.
If a new cert is added here and not activated yet, it will be already available in EntraID´s /federationmetadata/2007-06/federationmetadata.xml Endpoint. This means that the application could already accept SAML tokens which are signed by that new certificate (which is not yet active).

Therefore in my opinion the Detecting Silver SAML section in the Readme should be changed accordingly.

Any thoughts regarding this?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions