Finalizing TrustEngine config

Rod Widdowson rdw at steadingsoftware.com
Thu Jun 19 09:37:01 EDT 2014


This is somewhat tangentially related.

Brent and I discussed this some time ago. We need a centralized placed to
pull together the default key info providers.

Currently the custom schema parsers create this list by hand, and I see an
equivalent list in relying-party-system.xml.  I'm guessing that the trust
engines Scott is talking of adding will need them too.

This, particularly the first, is obviously fraught with issues - for
instance in V2 the parsers missed out when we added the
DEREncodedKeyProvider.

Would it be sensible to create a single centralized bean with this in?  If
so, where and what do we call it?

R

> -----Original Message-----
> From: dev-bounces at shibboleth.net [mailto:dev-bounces at shibboleth.net] On
> Behalf Of Cantor, Scott
> Sent: 19 June 2014 02:02
> To: Shib Dev
> Subject: Re: Finalizing TrustEngine config
> 
> On 6/18/14, 8:16 PM, "Brent Putman" <putmanb at georgetown.edu> wrote:
> 
> >
> >On 6/18/14 8:06 PM, Cantor, Scott wrote:
> >>
> >> >From the strictly outside perspective using it all, yes, it seems to
> >>fit
> >> together with the rest of the parameters and such.
> >
> >Ok.  Let's just think on it for a couple of days and talk about on
> >Friday's call.  If we decide to go forward with that idea, I can work on
> >it on Friday and earlier next week before I go away next Thursday.
> 
> Pending that, if you had time to look at changing the global-system
> definitions to include the usual chain of ExplicitKey and PKIX via
> metadata, that would get us past the alpha.
> 
> -- Scott
> 
> 
> --
> To unsubscribe from this list send an email to
dev-unsubscribe at shibboleth.net



More information about the dev mailing list