Questions about signing key pair in IdP

Tom Scavo trscavo at gmail.com
Tue Jul 10 12:07:31 EDT 2012


On Tue, Jul 10, 2012 at 11:51 AM, Cantor, Scott <cantor.2 at osu.edu> wrote:
> On 7/10/12 11:30 AM, "Tom Scavo" <trscavo at gmail.com> wrote:
>
>>If, OTOH, the two certificates are different, then key pair #2 is used
>>for:
>>
>>- message signing in conjunction with attribute query (if the IdP
>>supports that)
>>- SSL/TLS in conjunction with artifact query
>
> No

Sorry, typo. I meant to say that key pair #2 (AADescriptor) is used for:

- message signing in conjunction with attribute query
- SSL/TLS in conjunction with attribute query

while key pair #1 is used for everything else (including the artifact binding).

> in that case, it will fail, because artifact flows use the IDP role.

What will fail? Were you responding to my typo or something else?

Tom


More information about the users mailing list