Questions about signing key pair in IdP
ina.mueller at zdv.uni-tuebingen.de
ina.mueller at zdv.uni-tuebingen.de
Tue Jul 10 12:21:55 EDT 2012
ok, thank you all, that helped me much.
My main starting point was the IdPKeyRollover scenario, which made me
thinking about reasons for using a fully qualified certificate for
signing key pair in IdP instead of a self-signed cert ...
Ina
On 10.07.2012 18:12, Cantor, Scott wrote:
> On 7/10/12 12:07 PM, "Tom Scavo" <trscavo at gmail.com> wrote:
>>
>> Sorry, typo. I meant to say that key pair #2 (AADescriptor) is used for:
>>
>> - message signing in conjunction with attribute query
>> - SSL/TLS in conjunction with attribute query
>>
>> while key pair #1 is used for everything else (including the artifact
>> binding).
>
> Yes.
>
>>> in that case, it will fail, because artifact flows use the IDP role.
>>
>> What will fail? Were you responding to my typo or something else?
>
> The typo.
>
> -- Scott
>
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
>
More information about the users
mailing list