Validating metadata signature based on key in metadata
Stefan Rasmusson
rasmusson.stefan at gmail.com
Fri May 9 07:54:22 EDT 2014
On 9 May 2014 10:54, Rod Widdowson <rdw at steadingsoftware.com> wrote:
> You need to provide the public key externally via some OOB trust
> mechanism. You inject that into the signature validation filter which does
> all the rest of the work (like look in the metadata to see if the key is
> there). You really do not want to use the key in the metadata - there
> would be no trust.
>
Ya but SAML supports sending the key in the metadata. There would be a
trust if I could verify that the key is issued by a CA in the
SignatureValidationFilter.
--
Stefan
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/dev/attachments/20140509/2cc42ff4/attachment.html
More information about the dev
mailing list