PKIX and verification depth.

Ian Young ian at iay.org.uk
Wed Jul 2 10:31:44 EDT 2014


On 2 Jul 2014, at 15:23, Rod Widdowson <rdw at steadingsoftware.com> wrote:

> Yup, but what I don't know enough to know is whether that is a sensible
> enough default in non-IdP situations to break the current paradigm of
> requiring an (application defined) value.

If "1" would mean that the metadata would have to be directly signed by the trust root, then I'd reckon that to be a fine default.

	-- Ian



-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 5943 bytes
Desc: not available
Url : http://shibboleth.net/pipermail/dev/attachments/20140702/7e3e50fc/attachment-0001.bin 


More information about the dev mailing list