Decryption config

Brent Putman putmanb at georgetown.edu
Thu May 29 13:28:38 EDT 2014


On 5/28/14 10:06 PM, Cantor, Scott wrote:
> The SAML 2 tests are now encrypting a NameID of jdoe inside the
> AuthnRequest, and the IdP is successfully decrypting that. It worked with
> and without a KeyInfo.

Awesome.


>
> The errors when I had the wrong key ran on for about a mile, but that's
> probably a mix of things, certainly the second copy of the key I have
> configured isn't helping that.


Maybe we need to adjust some of the logging, at least stack traces, on
the failure cases of invalid keys, etc.  I'll see if there's anything
obvious that can be improved.  Of course, sometime you do really want
that stuff, so it's hard to know when it's really an error and when you
don't care.


More information about the dev mailing list