Validating metadata signature based on key in metadata
Cantor, Scott
cantor.2 at osu.edu
Fri May 9 10:24:53 EDT 2014
On 5/9/14, 9:09 AM, "Stefan Rasmusson" <rasmusson.stefan at gmail.com> wrote:
>If your key is issued by some CA I trust with this yes. What would else
>be the purpose of SAML allowing to send keys in the metadata?
That's part of XML Signature. How it gets used is subject to profiles.
And you are missing a critical piece if you think that a CA alone is
sufficient for trust if you choose to use PKIX. You need a binding between
the subject name and the logical name of the signer (and there is no such
name defined for a metadata signer, there's no entityID as there is in a
SAML message).
-- Scott
More information about the dev
mailing list