<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="generator" content="Windows Mail 17.5.9600.20413">
<style type="text/css"><!--html { font-family: "Color Emoji", "Calibri", "Segoe UI", "Meiryo", "Microsoft YaHei UI", "Microsoft JhengHei UI", "Malgun Gothic", "sans-serif"; }--></style><style data-externalstyle="true"><!--
p.MsoListParagraph, li.MsoListParagraph, div.MsoListParagraph {
margin-top:0in;
margin-right:0in;
margin-bottom:0in;
margin-left:.5in;
margin-bottom:.0001pt;
}
p.MsoNormal, li.MsoNormal, div.MsoNormal {
margin:0in;
margin-bottom:.0001pt;
}
p.MsoListParagraphCxSpFirst, li.MsoListParagraphCxSpFirst, div.MsoListParagraphCxSpFirst, 
p.MsoListParagraphCxSpMiddle, li.MsoListParagraphCxSpMiddle, div.MsoListParagraphCxSpMiddle, 
p.MsoListParagraphCxSpLast, li.MsoListParagraphCxSpLast, div.MsoListParagraphCxSpLast {
margin-top:0in;
margin-right:0in;
margin-bottom:0in;
margin-left:.5in;
margin-bottom:.0001pt;
line-height:115%;
}
--></style>
</head>
<body dir="ltr">
<div data-externalstyle="false" dir="ltr" style="font-family: 'Calibri', 'Segoe UI', 'Meiryo', 'Microsoft YaHei UI', 'Microsoft JhengHei UI', 'Malgun Gothic', 'sans-serif';font-size:12pt;">
<div>Commercial products will hopefully use an evaluated OS and its features for key management.</div>
<div><br>
</div>
<div>In Windows, there is a significant barrier to doing&nbsp;&#8220;better grade&#8221; key management. You typically need a certified engineer (and not one, like me, who from a American firm, got all the answers to cisco and windows certification tests given to him &#8230;alongside
 all the DoD personnel and Whitehouse IT support staff getting their&nbsp;&#8220;formalities&#8221; in order&#8230;).</div>
<div><br>
</div>
<div>Its hard to do key management right, commercially. For every dollar spent, 10 are spent by NSA defeating it or the staff operating the systems. Its hard to know how to invest in such a trust culture, where the subversion comes from within the social structures.</div>
<div><br>
</div>
<div>I know when I started this websso thing (in the idealism days), I worked hard to make the Ping Federate server use its HSM, with clustered nodes and full key management cloning, etc. While it did work, the firm just looked at him as daft (hinting that
 it was only there for procurement test passing, and not that ANYONE used it).<br>
</div>
<div data-signatureblock="true"><br>
</div>
<div style="padding-top: 5px; border-top-color: rgb(229, 229, 229); border-top-width: 1px; border-top-style: solid;">
<div><font face=" 'Calibri', 'Segoe UI', 'Meiryo', 'Microsoft YaHei UI', 'Microsoft JhengHei UI', 'Malgun Gothic', 'sans-serif'" style="line-height: 15pt; letter-spacing: 0.02em; font-family: &quot;Calibri&quot;, &quot;Segoe UI&quot;, &quot;Meiryo&quot;, &quot;Microsoft YaHei UI&quot;, &quot;Microsoft JhengHei UI&quot;, &quot;Malgun Gothic&quot;, &quot;sans-serif&quot;; font-size: 12pt;"><b>From:</b>&nbsp;<a href="mailto:cantor.2@osu.edu" target="_parent">Cantor,
 Scott</a><br>
<b>Sent:</b>&nbsp;&#8206;Friday&#8206;, &#8206;March&#8206; &#8206;28&#8206;, &#8206;2014 &#8206;12&#8206;:&#8206;22&#8206; &#8206;PM<br>
<b>To:</b>&nbsp;<a href="mailto:dev@shibboleth.net" target="_parent">Shib Dev</a></font></div>
</div>
<div><br>
</div>
<div dir="">
<div id="readingPaneBodyContent">On 3/28/14, 2:43 PM, &quot;Tom Scavo&quot; &lt;trscavo@gmail.com&gt; wrote:<br>
<br>
&gt;And speaking of metadata issues, AD FS has its share of those. It's<br>
&gt;unlikely their AD FS SP will be able to directly consume any metadata<br>
&gt;file you provide (maybe FEMMA will work, I don't know), which means<br>
&gt;you're trapped when it comes time to migrate a certificate in IdP<br>
&gt;metadata, or something along those lines.<br>
<br>
I took the OP's description to mean they'd likely be supplying their own<br>
metadata, and basic SAML metadata, even from a Shibboleth IdP or SP pretty<br>
much works fine.<br>
<br>
As far as migrating a key, sure, but that doesn't work with any commercial<br>
products, so ADFS is no worse. And obviously using a non-SAML protocol<br>
won't improve matters in any of these respects.<br>
<br>
-- Scott<br>
<br>
<br>
--<br>
To unsubscribe from this list send an email to dev-unsubscribe@shibboleth.net<br>
</div>
</div>
</div>
</body>
</html>