<style>
/* Changing the layout to use less space for mobiles */
@media screen and (max-device-width: 480px), screen and (-webkit-min-device-pixel-ratio: 2) {
#email-body { min-width: 30em !important; }
#email-page { padding: 8px !important; }
#email-banner { padding: 8px 8px 0 8px !important; }
#email-avatar { margin: 1px 8px 8px 0 !important; padding: 0 !important; }
#email-fields { padding: 0 8px 8px 8px !important; }
#email-gutter { width: 0 !important; }
}
</style>
<div id="email-body">
<table id="email-wrap" align="center" border="0" cellpadding="0" cellspacing="0" style="background-color:#f0f0f0;color:#000000;width:100%;">
<tr valign="top">
<td id="email-page" style="padding:16px !important;">
<table align="center" border="0" cellpadding="0" cellspacing="0" style="background-color:#ffffff;border:1px solid #bbbbbb;color:#000000;width:100%;">
<tr valign="top">
<td bgcolor="#ffffff" style="background-color:#ffffff;color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;line-height:1;"><img src="https://shibboleth.net/images/shib_240x83.png" alt="" style="vertical-align:top;" /></td>
</tr><tr valign="top">
<td id="email-banner" style="padding:32px 32px 0 32px;">
<table align="left" border="0" cellpadding="0" cellspacing="0" width="100%" style="width:100%;">
<tr valign="top">
<td style="color:#505050;font-family:Arial,FreeSans,Helvetica,sans-serif;padding:0;">
<img id="email-avatar" src="https://issues.shibboleth.net/jira/secure/useravatar?avatarId=10202" alt="" height="48" width="48" border="0" align="left" style="padding:0;margin: 0 16px 16px 0;" />
<div id="email-action" style="padding: 0 0 8px 0;font-size:12px;line-height:18px;">
<a class="user-hover" rel="putmanb@shibboleth.net" id="email_putmanb@shibboleth.net" href="https://issues.shibboleth.net/jira/secure/ViewProfile.jspa?name=putmanb%40shibboleth.net" style="color:#326ca6;">Brent Putman</a>
commented on <img src="https://issues.shibboleth.net/jira/images/icons/issuetypes/task.png" height="16" width="16" border="0" align="absmiddle" alt="Task"> <a style='color:#326ca6;text-decoration:none;' href='https://issues.shibboleth.net/jira/browse/OSJ-72'>OSJ-72</a>
</div>
<div id="email-summary" style="font-size:16px;line-height:20px;padding:2px 0 16px 0;">
<a style='color:#326ca6;text-decoration:none;' href='https://issues.shibboleth.net/jira/browse/OSJ-72'><strong>Support use of SignatureValidationFilter with dynamic metadata resolvers</strong></a>
</div>
</td>
</tr>
</table>
</td>
</tr>
<tr valign="top">
<td id="email-fields" style="padding:0 32px 32px 32px;">
<table border="0" cellpadding="0" cellspacing="0" style="padding:0;text-align:left;width:100%;" width="100%">
<tr valign="top">
<td id="email-gutter" style="width:64px;white-space:nowrap;"></td>
<td>
<table border="0" cellpadding="0" cellspacing="0" width="100%">
<tr valign="top">
<td colspan="2" style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 0 16px 0;width:100%;">
<div class="comment-block" style="background-color:#edf5ff;border:1px solid #dddddd;color:#000000;padding:12px;"><p>The draft strawman approach I've implemented so far is:</p>
<p>1) the SignatureValidationFilter gets an optional and injectable strategy Function<XMLObject,Set<String>> for dynamically calculating the Set<String> of dynamically trusted names, given a signed element that it is going to evaluate. (details below)</p>
<p>2) this generated Set is added to the trust engine criteria via a new TrustedNamesCriterion</p>
<p>3) the StaticPKIXValidationInformationResolver (the one we use for metadata signature validation) is augmented to optionally evaluate this criterion and return these names unioned with the set of static names configured into it at construction time.</p>
<p>This then lets PKIX trust evaluation proceed as usual, where effectively the signing cert in the ds:Signature is allowed to pass iff it meets the dynamically-derived trusted names (or static names if there were any).</p>
<p>Note that this isn't strictly only useful for the dynamic metadata resolver. It could also be used by the batch resolvers to allow PKIX trust rather than static trust, e.g. where an EntitiesDescriptor is signed by a federation whose @Name appears in the cert in one of the supported/configured places (typically a URI or DNS alt name, or the subject CN).</p>
<p>The basic strategy I have implemented for #1 so far is:</p>
<p>EntityDescriptor - extract entityID attribute<br/>
EntitiesDescriptor - extract Name attribute<br/>
RoleDescriptor - extract parent EntityDescriptor entityID attribute<br/>
AffiliationDescriptor - extract affiliationOwnerID attribute and parent EntityDescriptor entityID attribute</p>
<p>Scott, IIRC this strategy is similar to what you implemented for the SP (or at least talked about implementing...), insofar as the notion of trusting a cert that matched an expected entityID/Name derived from the context of the target Signature. Let me know if any of this sounds wonky or you see a problem.</p>
</div>
<div style="color:#505050;padding:4px 0 0 0;"> </div>
</td>
</tr>
</table>
</td>
</tr>
</table>
</td>
</tr>
</table>
</td><!-- End #email-page -->
</tr>
<tr valign="top">
<td style="color:#505050;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:10px;line-height:14px;padding: 0 16px 16px 16px;text-align:center;">
This message is automatically generated by JIRA.<br />
If you think it was sent incorrectly, please contact your JIRA administrators<br />
For more information on JIRA, see: <a style='color:#326ca6;' href='http://www.atlassian.com/software/jira'>http://www.atlassian.com/software/jira</a>
</td>
</tr>
</table><!-- End #email-wrap -->
</div><!-- End #email-body -->