<div dir="ltr"><div class="gmail_extra"><br><div class="gmail_quote">On 9 May 2014 10:54, Rod Widdowson <span dir="ltr">&lt;<a href="mailto:rdw@steadingsoftware.com" target="_blank">rdw@steadingsoftware.com</a>&gt;</span> wrote:<br>

<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div id=":tb" class="a3s" style="overflow:hidden">You need to provide the public key externally via some OOB trust mechanism.  You inject that into the signature validation filter which does all the rest of the work (like look in the metadata to see if the key is there).  You really do not want to use the key in the metadata - there would be no trust.<br>

</div></blockquote></div><br><br>Ya but SAML supports sending the key in the metadata. There would be a trust if I could verify that the key is issued by a CA in the SignatureValidationFilter. </div><div class="gmail_extra">

<br></div><div class="gmail_extra"><br clear="all"><div><div><br></div><div>--</div>Stefan</div>
</div></div>