Finalizing TrustEngine config
Rod Widdowson
rdw at steadingsoftware.com
Thu Jun 19 09:37:01 EDT 2014
This is somewhat tangentially related.
Brent and I discussed this some time ago. We need a centralized placed to
pull together the default key info providers.
Currently the custom schema parsers create this list by hand, and I see an
equivalent list in relying-party-system.xml. I'm guessing that the trust
engines Scott is talking of adding will need them too.
This, particularly the first, is obviously fraught with issues - for
instance in V2 the parsers missed out when we added the
DEREncodedKeyProvider.
Would it be sensible to create a single centralized bean with this in? If
so, where and what do we call it?
R
> -----Original Message-----
> From: dev-bounces at shibboleth.net [mailto:dev-bounces at shibboleth.net] On
> Behalf Of Cantor, Scott
> Sent: 19 June 2014 02:02
> To: Shib Dev
> Subject: Re: Finalizing TrustEngine config
>
> On 6/18/14, 8:16 PM, "Brent Putman" <putmanb at georgetown.edu> wrote:
>
> >
> >On 6/18/14 8:06 PM, Cantor, Scott wrote:
> >>
> >> >From the strictly outside perspective using it all, yes, it seems to
> >>fit
> >> together with the rest of the parameters and such.
> >
> >Ok. Let's just think on it for a couple of days and talk about on
> >Friday's call. If we decide to go forward with that idea, I can work on
> >it on Friday and earlier next week before I go away next Thursday.
>
> Pending that, if you had time to look at changing the global-system
> definitions to include the usual chain of ExplicitKey and PKIX via
> metadata, that would get us past the alpha.
>
> -- Scott
>
>
> --
> To unsubscribe from this list send an email to
dev-unsubscribe at shibboleth.net
More information about the dev
mailing list