IdP credentials for delegation Assertion signature validation

Cantor, Scott cantor.2 at osu.edu
Thu Aug 20 22:05:43 EDT 2015


On 8/20/15, 10:00 PM, "dev on behalf of Brent Putman" <dev-bounces at shibboleth.net on behalf of putmanb at georgetown.edu> wrote:

>No, I don't think so.  There could be many signing creds and the exact one that was used certainly can't be assumed to be in the default list.  It might have been an RP-specific one not specified in the default SecurityConfiguration.

I'm not sure we necessarily have to make it that complex.

The intention is that the credentials would be declared in one place, even if they're applied/used in different situations.

>Either way, the thing I guess I would need agreement on is that: in order for this to work, I believe we'd need to assume a new bean structure in conf/credentials.xml.  We'd need to have the deployer wrap all the defined signing credentials in a new list, e.g.

Granted, what I'm suggesting would still have to presume a surrounding structure that's not currently there.

But if you want to do the work of creating a CredentialService, which certainly isn't a bad thing, we probably should migrate everything to that and come up with a way to do that backward-compatibly.

-- Scott



More information about the dev mailing list