<div dir="ltr"><div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Since this is about "a trust engine for enforcing certificate policies<br>
are satisfied", I wondered if you are aware of<br>
<a href="https://issues.shibboleth.net/jira/browse/JXT-98" target="_blank">https://issues.shibboleth.net/jira/browse/JXT-98</a> (which also made its<br>
way into OpenSAML 3, see OSJ-28)?<br></blockquote><div><br></div><div>I was not aware, thanks for pointing that out. In my case it's easier to do the typical trust check with the container, then supplement with my custom policy-based trust engine. If we ever switch to the PIKX trust engine, then I think we could do what we need with out-of-the-box components exclusively.</div><div><br></div><div>Thanks,</div><div>M<a href="mailto:dev-unsubscribe@shibboleth.net" target="_blank"></a><br>
</div><div><br></div></div></div>