<style>
/* Changing the layout to use less space for mobiles */
@media screen and (max-device-width: 480px), screen and (-webkit-min-device-pixel-ratio: 2) {
    #email-body { min-width: 30em !important; }
    #email-page { padding: 8px !important; }
    #email-banner { padding: 8px 8px 0 8px !important; }
    #email-avatar { margin: 1px 8px 8px 0 !important; padding: 0 !important; }
    #email-fields { padding: 0 8px 8px 8px !important; }
    #email-gutter { width: 0 !important; }
}
</style>
<div id="email-body">
<table id="email-wrap" align="center" border="0" cellpadding="0" cellspacing="0" style="background-color:#f0f0f0;color:#000000;width:100%;">
    <tr valign="top">
        <td id="email-page" style="padding:16px !important;">
            <table align="center" border="0" cellpadding="0" cellspacing="0" style="background-color:#ffffff;border:1px solid #bbbbbb;color:#000000;width:100%;">
                <tr valign="top">
                    <td bgcolor="#ffffff" style="background-color:#ffffff;color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;line-height:1;"><img src="https://shibboleth.net/images/shib_240x83.png" alt="" style="vertical-align:top;" /></td>
                </tr><tr valign="top">
    <td id="email-banner" style="padding:32px 32px 0 32px;">

                
        
        
            <table align="left" border="0" cellpadding="0" cellspacing="0" width="100%" style="width:100%;">
    <tr valign="top">
        <td style="color:#505050;font-family:Arial,FreeSans,Helvetica,sans-serif;padding:0;">
                                        <img id="email-avatar" src="https://issues.shibboleth.net/jira/secure/useravatar?avatarId=10202" alt="" height="48" width="48" border="0" align="left" style="padding:0;margin: 0 16px 16px 0;" />
                        <div id="email-action" style="padding: 0 0 8px 0;font-size:12px;line-height:18px;">
                                    <a class="user-hover" rel="zccx04fxbfekk/ldylvfqohcyf4=@https://aai-logon.switch.ch/idp/shibboleth" id="email_zccx04fxbfekk/ldylvfqohcyf4=@https://aai-logon.switch.ch/idp/shibboleth" href="https://issues.shibboleth.net/jira/secure/ViewProfile.jspa?name=zccx04fxbfekk%2Fldylvfqohcyf4%3D%40https%3A%2F%2Faai-logon.switch.ch%2Fidp%2Fshibboleth" style="color:#326ca6;">Kaspar Brand</a>
     commented on <img src="https://issues.shibboleth.net/jira/images/icons/newfeature.gif" height="16" width="16" border="0" align="absmiddle" alt="New Feature"> <a style='color:#326ca6;text-decoration:none;' href='https://issues.shibboleth.net/jira/browse/OSJ-10'>OSJ-10</a>
            </div>
                        <div id="email-summary" style="font-size:16px;line-height:20px;padding:2px 0 16px 0;">
                <a style='color:#326ca6;text-decoration:none;' href='https://issues.shibboleth.net/jira/browse/OSJ-10'><strong>Add support for configuring PKIX policy checking in the PKIX trust engine</strong></a>
            </div>
                    </td>
    </tr>
</table>
    </td>
</tr>
<tr valign="top">
    <td id="email-fields" style="padding:0 32px 32px 32px;">
        <table border="0" cellpadding="0" cellspacing="0" style="padding:0;text-align:left;width:100%;" width="100%">
            <tr valign="top">
                <td id="email-gutter" style="width:64px;white-space:nowrap;"></td>
                <td>
                    <table border="0" cellpadding="0" cellspacing="0" width="100%">
                        <tr valign="top">
    <td colspan="2" style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 0 16px 0;width:100%;">
        <div class="comment-block" style="background-color:#edf5ff;border:1px solid #dddddd;color:#000000;padding:12px;"><p>Given that the IdP v3 release date has shifted quite a bit meanwhile, is this something which could also be considered for inclusion into 2.4? The missing pieces are only few, I think... <tt>&lt;TrustedName&gt;</tt> is already there - it's only the support for <tt>&lt;PolicyOID&gt;</tt> element(s) and the policy checking options which need to be added.</p>

<p>A TrustEngine configuration could then look like</p>

<div class="code panel" style="border-width: 1px;"><div class="codeContent panelContent">
<pre class="code-xml"><span class="code-tag">&lt;security:TrustEngine id=<span class="code-quote">"shibboleth.MetadataTrustEngine"</span> xsi:type=<span class="code-quote">"security:StaticPKIXSignature"</span>&gt;</span>
  <span class="code-tag">&lt;security:TrustedName&gt;</span>Foo Federation Metadata Signer<span class="code-tag">&lt;/security:TrustedName&gt;</span>
  &lt;security:ValidationInfo id=<span class="code-quote">"FooCA"</span> 
                           xsi:type=<span class="code-quote">"security:PKIXFilesystem"</span>
                           verifyDepth=<span class="code-quote">"2"</span>&gt;
    <span class="code-tag">&lt;security:Certificate&gt;</span>/opt/shibboleth-idp/credentials/FooCA.crt.pem<span class="code-tag">&lt;/security:Certificate&gt;</span>
  <span class="code-tag">&lt;/security:ValidationInfo&gt;</span>
  <span class="code-tag">&lt;security:PolicyOID&gt;</span>2.16.756.1.2.6.7.1.1<span class="code-tag">&lt;/security:PolicyOID&gt;</span>
  &lt;security:ValidationOptions xsi:type=<span class="code-quote">"security:CertPathValidationOptionsType"</span>
                              forceRevocationEnabled=<span class="code-quote">"true"</span>
                              policyMappingInhibit=<span class="code-quote">"true"</span>
                              anyPolicyInhibit=<span class="code-quote">"true"</span>/&gt;
<span class="code-tag">&lt;/security:TrustEngine&gt;</span></pre>
</div></div>

<p>(where <tt>PolicyOID</tt> is implemented through <tt>setInitialPolicies</tt>, <tt>policyMappingInhibit</tt> through <tt>setPolicyMappingInhibited</tt> and <tt>anyPolicyInhibit</tt> through <tt>setAnyPolicyInhibited</tt>, to keep the naming consistent with those from the SP, see <a href="http://svn.shibboleth.net/view/cpp-xmltooling?view=revision&amp;revision=899" class="external-link">http://svn.shibboleth.net/view/cpp-xmltooling?view=revision&amp;revision=899</a> and <a href="https://issues.shibboleth.net/jira/browse/CPPXT-78" title="Support configuration of name and policy restrictions for the signature metadata filter (signing certificate)"><del>CPPXT-78</del></a>).</p>

<p>The URL for the CertPath doc is now <a href="http://docs.oracle.com/javase/6/docs/api/java/security/cert/PKIXParameters.html" class="external-link">http://docs.oracle.com/javase/6/docs/api/java/security/cert/PKIXParameters.html</a>, BTW (and cf. also <a href="http://docs.oracle.com/javase/6/docs/technotes/guides/security/certpath/CertPathProgGuide.html#PKIXParameters" class="external-link">http://docs.oracle.com/javase/6/docs/technotes/guides/security/certpath/CertPathProgGuide.html#PKIXParameters</a>)</p></div>
        <div style="color:#505050;padding:4px 0 0 0;">                </div>
    </td>
</tr>
                    </table>
                </td>
            </tr>
        </table>
    </td>
</tr>













            </table>
        </td><!-- End #email-page -->
    </tr>
    <tr valign="top">
        <td style="color:#505050;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:10px;line-height:14px;padding: 0 16px 16px 16px;text-align:center;">
            This message is automatically generated by JIRA.<br />
            If you think it was sent incorrectly, please contact your JIRA administrators<br />
            For more information on JIRA, see: <a style='color:#326ca6;' href='http://www.atlassian.com/software/jira'>http://www.atlassian.com/software/jira</a>
        </td>
    </tr>
</table><!-- End #email-wrap -->
</div><!-- End #email-body -->