Exception when creating the signature using OpenSAML lib

Cantor, Scott cantor.2 at osu.edu
Thu Nov 1 19:36:10 EDT 2012


On 11/1/12 6:55 PM, "Yaowen Tu" <yaowen.tu at gmail.com> wrote:
>
>I understand that this question is related to what we have just
>discussed. Using the key inside the signature is not secure. We should
>either use PKI or other secure channel for example get the key directly.
>If I want to use PKI, could you show me some sample
> code if there is any? or give me some hints about what I should do? I
>didn't find much information in wiki.

You have to let it extract the key from the signature, verify it, and then
apply a trust engine to the key at that point to decide whether to trust
it. Conceptually anyway.

-- Scott




More information about the dev mailing list