Questions about signing key pair in IdP
Tom Scavo
trscavo at gmail.com
Tue Jul 10 12:07:31 EDT 2012
On Tue, Jul 10, 2012 at 11:51 AM, Cantor, Scott <cantor.2 at osu.edu> wrote:
> On 7/10/12 11:30 AM, "Tom Scavo" <trscavo at gmail.com> wrote:
>
>>If, OTOH, the two certificates are different, then key pair #2 is used
>>for:
>>
>>- message signing in conjunction with attribute query (if the IdP
>>supports that)
>>- SSL/TLS in conjunction with artifact query
>
> No
Sorry, typo. I meant to say that key pair #2 (AADescriptor) is used for:
- message signing in conjunction with attribute query
- SSL/TLS in conjunction with attribute query
while key pair #1 is used for everything else (including the artifact binding).
> in that case, it will fail, because artifact flows use the IDP role.
What will fail? Were you responding to my typo or something else?
Tom
More information about the users
mailing list