Decryption config

Brent Putman putmanb at georgetown.edu
Thu May 29 13:31:48 EDT 2014


On 5/28/14 11:32 PM, Cantor, Scott wrote:
> This also works now for legacy relying-party.xml usage, but I did that by
> overloading the signingCredentialRef to be the decryption key, which may
> not be what we want. We'd have to extend the schema to avoid that, of
> course, or just not support it.


It seems wrong to overload it for encryption when signing is right in
the attribute name.  Esp since in v3 we're trying to make the signing
and encryption creds distinct, in general.  I'd argue for either adding
an optional encryptionCredentialRef, if it's easy to do, or else just
not supporting with the legacy syntax.



More information about the dev mailing list