Validating metadata signature based on key in metadata

Stefan Rasmusson rasmusson.stefan at gmail.com
Fri May 9 09:09:20 EDT 2014


If your key is issued by some CA I trust with this yes. What would else be
the purpose of SAML allowing to send keys in the metadata?


--
Stefan


On 9 May 2014 14:14, Rod Widdowson <rdw at steadingsoftware.com> wrote:

> > Ya but SAML supports sending the key in the metadata. There would be a
> trust if I could verify that the key is issued by a CA in the
> SignatureValidationFilter.
>
> So I take some random metadata, insert my key into it, sign it with that
> key and you'll trust it?  Or am I missing something?
>
> --
> To unsubscribe from this list send an email to
> dev-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/dev/attachments/20140509/8e30b083/attachment.html 


More information about the dev mailing list