Questions about signing key pair in IdP

ina.mueller at zdv.uni-tuebingen.de ina.mueller at zdv.uni-tuebingen.de
Tue Jul 10 12:21:55 EDT 2012


ok, thank you all, that helped me much.

My main starting point was the IdPKeyRollover scenario, which made me 
thinking about reasons for using a fully qualified certificate for 
signing key pair in IdP instead of a self-signed cert ...

Ina



On 10.07.2012 18:12, Cantor, Scott wrote:
> On 7/10/12 12:07 PM, "Tom Scavo" <trscavo at gmail.com> wrote:
>>
>> Sorry, typo. I meant to say that key pair #2 (AADescriptor) is used for:
>>
>> - message signing in conjunction with attribute query
>> - SSL/TLS in conjunction with attribute query
>>
>> while key pair #1 is used for everything else (including the artifact
>> binding).
>
> Yes.
>
>>> in that case, it will fail, because artifact flows use the IDP role.
>>
>> What will fail? Were you responding to my typo or something else?
>
> The typo.
>
> -- Scott
>
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
>



More information about the users mailing list