Make X509AuthServlet extensible

Marvin Addison marvin.addison at gmail.com
Thu May 7 07:55:24 EDT 2015


>
> Since this is about "a trust engine for enforcing certificate policies
> are satisfied", I wondered if you are aware of
> https://issues.shibboleth.net/jira/browse/JXT-98 (which also made its
> way into OpenSAML 3, see OSJ-28)?
>

I was not aware, thanks for pointing that out. In my case it's easier to do
the typical trust check with the container, then supplement with my custom
policy-based trust engine. If we ever switch to the PIKX trust engine, then
I think we could do what we need with out-of-the-box components exclusively.

Thanks,
M <dev-unsubscribe at shibboleth.net>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/dev/attachments/20150507/77edb5d7/attachment.html>


More information about the dev mailing list