Security defaults
Cantor, Scott
cantor.2 at osu.edu
Sun May 11 20:36:07 EDT 2014
I made some progress, the auto-wired credential is gone and is being
pulled from the relying-party.xml configuration now.
I also baked in what I believe are the appropriate signing/encryption
predicates into the profile configurations. I think these are being
partially overridden by Rod's defaults in the Spring parsers, but we
should be able to remove those defaults now, and only install predicates
if there's actually a configuration property set.
To get the signing actions to work, I had to actually populate signing,
digest, and c14n algorithms in the config file, there don't appear to be
any defaults coming from OpenSAML at this point. I don't know if that's
the eventual state of things or not.
The encryption parameter resolver isn't working for me yet either, but I
haven't dug into that fully yet.
-- Scott
More information about the dev
mailing list