Metadata Generation
Tom Scavo
trscavo at gmail.com
Thu Sep 25 07:50:37 EDT 2014
On Thu, Sep 25, 2014 at 6:17 AM, Rod Widdowson <rdw at steadingsoftware.com> wrote:
>
> Now that we have separate certificates for
> signing and for the back-channel
You do? Hmm, what's the rationale for that?
> does this mean that *both* certs need to
> be listed for the <IDPSSODescriptor>
Only in the presence of a SOAP endpoint, but I suppose so, yes.
> but only the back channel one for the
> <AttributeAuthorityDescriptor>?
Don't you support signing on the back channel? Not sure anyone uses it but...
> Do they both need to be specified as use="signing"?
Yes of course.
> Is it worthwhile adding an encryption key in as well (even though we don't
> use or configure it). I would have through not (plus this needs more
> installation mechanism)
If you don't support it, what's the point?
(Other) Tom
More information about the dev
mailing list