Metadata Generation

Tom Scavo trscavo at gmail.com
Thu Sep 25 07:50:37 EDT 2014


On Thu, Sep 25, 2014 at 6:17 AM, Rod Widdowson <rdw at steadingsoftware.com> wrote:
>
> Now that we have separate certificates for
> signing and for the back-channel

You do? Hmm, what's the rationale for that?

> does this mean that *both* certs need to
> be listed for the <IDPSSODescriptor>

Only in the presence of a SOAP endpoint, but I suppose so, yes.

> but only the back channel one for the
> <AttributeAuthorityDescriptor>?

Don't you support signing on the back channel? Not sure anyone uses it but...

> Do they both need to be specified as use="signing"?

Yes of course.

> Is it worthwhile adding an encryption key in as well (even though we don't
> use or configure it).  I would have through not (plus this needs more
> installation mechanism)

If you don't support it, what's the point?

(Other) Tom


More information about the dev mailing list