include SignatureValidation filter with FileBackedHTTPMetadataProvider

Tom Scavo trscavo at gmail.com
Tue Dec 19 12:53:12 EST 2017


On Tue, Dec 19, 2017 at 12:31 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:
>
> Please revert it.

Done. Sorry for the false start.

> I still don't know what you mean to say...

If the metadata is NOT signed, do not use FileBackedHTTPMetadataProvider.

Why? Because if you do, there's no security upon startup.

Tom


More information about the dev mailing list