SignAssertions action not needed ?

Cantor, Scott cantor.2 at osu.edu
Tue Feb 4 13:31:39 EST 2014


On 2/4/14, 1:21 PM, "Brent Putman" <putmanb at georgetown.edu> wrote:
>
>Also need to settle on and work out how the whitelist/blacklist
>algorithm URI's from DecryptionParameters and
>SignatureValidationParameters actually get applied, but I think that's
>probably just updating the Decrypter and SignatureValidator code to
>support those inputs, in some fashion.  Since I just reminded myself of
>it, I'll work on that this week.
> 

Yes, I'm presuming we want blacklisting to be an input to the construction
of the parameters, not imposed after. On the validation side, it does
probably have to be part of the validation process, possibly as just a
supplementary validator added to others, or maybe it's just a policy
rule/message handler.

-- Scott




More information about the dev mailing list