help signing metadata

Cantor, Scott cantor.2 at osu.edu
Tue Oct 25 15:42:37 BST 2011


On 10/25/11 10:33 AM, "Jonathan Bricker" <jbricker at exacttarget.com> wrote:

>How would I have to set up the SP to accept metadata signed from a list
>of accepted CAs?  It sounds like it is impossible from what was said
>below.

A list of static CAs is specified using a StaticPKIX trust engine with a
chain of credential resolvers pointing to the CAs, but there is no way
until 2.5 to specify the name of a signing certificate if a group of
entities is being signed.

But using a list of CAs has nothing to do with nested signatures or
multiple signers. You're going to have to be more explicit about what
you're trying to accomplish.

-- Scott



More information about the users mailing list