help signing metadata

Cantor, Scott cantor.2 at osu.edu
Tue Oct 25 18:10:12 BST 2011


On 10/25/11 1:01 PM, "Jonathan Bricker" <jbricker at exacttarget.com> wrote:

>Would it be better to check the certs at runtime when a request comes in
>or write a plugin to check the cert in the metadata?

I don't know anything about your requirements or your trust model. How you
need to supply and acquire metadata and what assumptions you can make if
any about the PKI and the content of the certificates is what drives all
of this.

You seem to want a simple answer. So, here goes. If you care about the
certs, I think you're doing it wrong.

-- Scott



More information about the users mailing list