Cert Issue from SP
Cantor, Scott
cantor.2 at osu.edu
Thu Feb 2 18:12:21 GMT 2012
> I think it's not parsing correctly what is being sent in the KeyInfo
> form param on POST SimpleSign. I believe that's the only way that code
> path is reached in our shipped security policy rules.
Ok.
> That actually is coming from the rule processing. The
> not-yet-commons-ssl library has some helpers that are used for
> processing (decoding) keys and certs in various places, so that's why
> you see the "ssl" show up in the package name there. But it doesn't
> really have anything to do with SSL.
My mistake.
I have a hard time believing anybody is using SimpleSign. Is it possible any of that gets invoked in the Redirect case? Even if not permitted by spec, if you passed a KeyInfo parameter, for example?
-- Scott
More information about the users
mailing list