Security parsing - signing and defaults

Cantor, Scott cantor.2 at osu.edu
Fri Apr 25 20:27:33 EDT 2014


On 4/25/14, 12:18 PM, "Rod Widdowson" <rdw at steadingsoftware.com> wrote:
>
>€  Thus it becomes acceptable for
>ProfileConfiguration#getSecurityConfiguration() to return null meaning
>³use
>the default².

Or rather we'll always use the default, but a null there just means not to
feed anything RP-specific into OpenSAML.

>€  The defaultSigning key will be used to set up a SecuirtyConfiguration
>with *only* a SignatureSigningConfiguration set in it.  This
>SignatureSigningConfiguration will *only* have the credential set.  The
>rest
>of the code knows/will know how to handle defaults from further on down.

I don't know that there's nothing else in the old schema that relates to
those SecurityConfiguration interfaces, but I don't think there is.

-- Scott




More information about the dev mailing list