Validating metadata signature based on key in metadata

Cantor, Scott cantor.2 at osu.edu
Fri May 9 10:24:53 EDT 2014


On 5/9/14, 9:09 AM, "Stefan Rasmusson" <rasmusson.stefan at gmail.com> wrote:

>If your key is issued by some CA I trust with this yes. What would else
>be the purpose of SAML allowing to send keys in the metadata?

That's part of XML Signature. How it gets used is subject to profiles.

And you are missing a critical piece if you think that a CA alone is
sufficient for trust if you choose to use PKIX. You need a binding between
the subject name and the logical name of the signer (and there is no such
name defined for a metadata signer, there's no entityID as there is in a
SAML message).

-- Scott




More information about the dev mailing list