InlineX509DataProvider skips credential extraction if only X509SKI is present
Cantor, Scott
cantor.2 at osu.edu
Fri Dec 21 12:57:02 EST 2012
On 12/21/12 12:03 PM, "Andreas Hartmann" <andreas at apache.org> wrote:
>
>I hope that the ExplicitKeySignatureTrustEngine will still be able to
>validate the signature by falling back to the trusted credentials. I'll
>investigate why this fails at the moment.
I would take any follow up to the dev list. If I'm not confused, you're
not using Shibboleth at all.
Secondly, the trust engines in general are designed to validate against
sources of credentials like metadata or an explicitly configured key. HoK
SSO is just not the same idea, unless you're talking about validating the
IdP's signature, rather than the subject confirmation against the client's
key. Those are different operations.
-- Scott
More information about the users
mailing list