Finalizing TrustEngine config

Brent Putman putmanb at georgetown.edu
Wed Jun 18 19:58:34 EDT 2014


On 6/18/14 7:50 PM, Brent Putman wrote:
>
> Yes, seems natural.  Am I inferring then that you think the preferred
> way would be to switch gears and use the SignatureTrustEngine on the
> SignatureValidationParameters?  I'm sure that's doable in the
> signature handlers, but in looking at them it's not as trivial as I'd
> hoped, because of the way the generic TrustEngine-oriented
> superclasses are written.

Of course, if we did a complete 180, and completely removed the trust
engine that is set on the handlers in favor of the
SignatureValidationParameters from the message context, refactored the
base classes, etc, that would simplify things considerably.

If we did that, presumably we'd have to define some sort of new
-Configuration, -Parameters and -Resolver to handle the client cert case
using a cert TrustEngine.

 

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/dev/attachments/20140618/dcd0e86f/attachment-0001.html 


More information about the dev mailing list