IdP credentials for delegation Assertion signature validation
Cantor, Scott
cantor.2 at osu.edu
Thu Aug 20 23:03:42 EDT 2015
On 8/20/15, 10:40 PM, "dev on behalf of Brent Putman" <dev-bounces at shibboleth.net on behalf of putmanb at georgetown.edu> wrote:
>I'll think about that. That aspect might be easier, but as I said, right now the components assume they are going to be wired in the flow beans. I don't "resolve" the Assertion validator or its constituent SignatureTrustEngine for example. To use creds injected on the profile config I think I'd have to switch some things to be constructed on the fly at runtime based on the injected creds. So that part would be more complex.
I guess a bit maybe, but I assumed not too bad.
>Actually there's also the issue of *which* profile config. I think it's also back to the "to whom did I sign" question. Unless we just injected the all the creds on all the profile configs (on the abstract one, etc). Then we could pick anyone (e.g. the one already resolved for the SAML requester). But that sort of doesn't feel right.
No, but I think you need to look up the profile config *somehow* anyway, right? And I thought it was associated with the requester of the delegation token, by virtue of the request it's issuing to the SSOS, but my memory's not that fresh on things.
-- Scott
More information about the dev
mailing list