Shibboleth2 IdP TrustEngine Extension using DANE, is it the right way?

Cantor, Scott cantor.2 at osu.edu
Tue May 8 15:08:57 BST 2012


On 5/8/12 2:46 AM, "Christoffer Holmstedt"
<christoffer.holmstedt at gmail.com> wrote:
>
>At the moment there is no mention of CERT RRs in the DANE use cases or
>drafts. If we just look at the draft that is specfic to TLS
>communication (http://datatracker.ietf.org/doc/draft-ietf-dane-protocol/)
>it will be up to the zone administrator or owner to choose whether you
>want to have self-signed certificate or not.

If you care whether it is, then you are evaluating the certificate *as a
certificate*. Wheher you meant to do that wasn't clear from your original
message, in which you implied merely a comparison against something in the
signature.

>Yes, we're aware of this. The first idea was to actually use the
>domain of the URL at which the metadata is published, though I read
>somewhere that within MetadataFilters or TrustEngines (can't remember
>where or find it now for that matter) you only have access to the
>actual downloaded metadata not the URL where it "comes" from. This may
>very well be wrong so please correct me if so.

I suspect that's correct.

-- Scott



More information about the dev mailing list