Decryption config

Cantor, Scott cantor.2 at osu.edu
Thu May 29 15:43:04 EDT 2014


On 5/29/14, 1:31 PM, "Brent Putman" <putmanb at georgetown.edu> wrote:
>
>It seems wrong to overload it for encryption when signing is right in
>the attribute name.  Esp since in v3 we're trying to make the signing
>and encryption creds distinct, in general.  I'd argue for either adding
>an optional encryptionCredentialRef, if it's easy to do, or else just
>not supporting with the legacy syntax.

I think it's easy to do, the downside is just that the IdP won't decrypt
by default with a legacy configuration, but I don't think that will matter
much since it doesn't support it at all now anyway.

-- Scott




More information about the dev mailing list