Signature validation filter config

Cantor, Scott cantor.2 at osu.edu
Mon Apr 14 13:44:07 EDT 2014


On 4/14/14, 1:14 PM, "Brent Putman" <putmanb at georgetown.edu> wrote:
>
>I can think of at least 2 use cases where the user would want or need to
>wire in multiple validation certs/keys: 1)  for the dynamic metadata
>resolvers(s), where you really do have multiple concurrent trust
>material

The problem with (1) is that you lose naming constraints. Without a more
complex algorithm, the single key would be usable to vouch for any query
result, and that's not really what you want, necessarily, so my guess is
we'll need something more than just listing certificates anyway.

>If we do go with the attributes option, should we consider making those
>XML delimited lists of certs/keys?  Maybe that's too complicated...

It would be less so if we could resolve relative paths like the SP does,
and just find credentials in idp/conf/creds/

-- Scott




More information about the dev mailing list