Decryption config
Brent Putman
putmanb at georgetown.edu
Thu May 29 17:19:50 EDT 2014
On 5/29/14 4:44 PM, Cantor, Scott wrote:
> Only if I reuse an existing setting, otherwise there's no way to no what
> key to use. If I add a setting to specify the encryption key, that would
> have to be set, and no existing config has it, so you wouldn't get t he
> support.
Oh, I see. You meant an actual legacy config (an actual existing file),
not someone who just wanted to use the legacy config generally and
possibly add the decryption cred if they needed.
So I'd personally still say then either not support it at all, or add a
new attribute for the decryption cred.
Also, not to point out the obvious, but reusing the signing cred ref
doesn't necessarily work at a technical level. It obviously does happen
to work if it's an RSA key (presumably the 99%+ case today for existing
configs), but if/when people start moving to EC and start signing that
way, that would break. (At least until we start supporting the ECDH
stuff, and I'm not sure about the particulars, still need to fully grok
that).
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/dev/attachments/20140529/e8a79aae/attachment.html
More information about the dev
mailing list