Validating metadata signature based on key in metadata

Stefan Rasmusson rasmusson.stefan at gmail.com
Fri May 9 07:54:22 EDT 2014


On 9 May 2014 10:54, Rod Widdowson <rdw at steadingsoftware.com> wrote:

> You need to provide the public key externally via some OOB trust
> mechanism.  You inject that into the signature validation filter which does
> all the rest of the work (like look in the metadata to see if the key is
> there).  You really do not want to use the key in the metadata - there
> would be no trust.
>


Ya but SAML supports sending the key in the metadata. There would be a
trust if I could verify that the key is issued by a CA in the
SignatureValidationFilter.



--
Stefan
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/dev/attachments/20140509/2cc42ff4/attachment.html 


More information about the dev mailing list