Resolving credentials from Metadata in OpenSAML 3.0

punit ashra punitashra at gmail.com
Tue Aug 16 04:59:59 EDT 2016


Hi Lasse,

You can use
KeyInfoCredentialResolver keyInfoCredResolver =
DefaultSecurityConfigurationBootstrap.buildBasicInlineKeyInfoCredentialResolver();

Or use SAMLTestSupport.buildBasicInlineKeyInfoResolver()

Thanks,
Punit

On Tue, Aug 16, 2016 at 2:25 PM, Lasse Højgaard <lash at stibosystems.com>
wrote:

> Hi all,
>
> I'm currently implementing SSO using OpenSAML. I have established trust
> between my IdP and the SP that I'm implementing.
>
> What I'm trying to do is: fetch the credential with usagetype "SIGNING"
> from the metadata of the IdP and validate that signature using a
> SignatureTrustEngine.
> What I have so far is this:
>
>         public SignatureTrustEngine getSignatureTrustEngine() throws
> ComponentInitializationException{
>                 BasicRoleDescriptorResolver basicRoleDescriptorResolver =
> new BasicRoleDescriptorResolver(metadataResolver);
>                 MetadataCredentialResolver mcr = new
> MetadataCredentialResolver();
>
>                 mcr.setRoleDescriptorResolver(
> basicRoleDescriptorResolver);
>                 mcr.initialize();
>                 KeyInfoCredentialResolver keyInfoCredentialResolver = mcr.
> getKeyInfoCredentialResolver();
>                 ExplicitKeySignatureTrustEngine trustEngine = new
> ExplicitKeySignatureTrustEngine(mcr, keyInfoCredentialResolver);
>                 SignatureTrustEngine sigTrustEngine = trustEngine;
>                 return sigTrustEngine;
>         }
>
> My question is:
> How do I get a KeyInfoCredentialResolver? I've looked at the documentation
> for V2.0 - but that doesn't help me much:
> https://wiki.shibboleth.net/confluence/display/OpenSAML/
> OSTwoUserManJavaDSIG
>
>
> Lasse Højgaard
> Consultant
>
> Stibo Systems A/S
>   |  8270  |  Højbjerg  |  Denmark
> T +45 89 39 13 23  |  M +45 20 42 45 96
> lash at stibosystems.com  |
>
> --
> To unsubscribe from this list send an email to
> dev-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/dev/attachments/20160816/f3f60fb7/attachment-0001.html>


More information about the dev mailing list