Questions about signing key pair in IdP

Cantor, Scott cantor.2 at osu.edu
Tue Jul 10 12:28:58 EDT 2012


On 7/10/12 12:21 PM, "ina.mueller at zdv.uni-tuebingen.de"
<ina.mueller at zdv.uni-tuebingen.de> wrote:
>
>My main starting point was the IdPKeyRollover scenario, which made me
>thinking about reasons for using a fully qualified certificate for
>signing key pair in IdP instead of a self-signed cert ...

It doesn't help the way you think it does and using them for signing, in
particular, is almost always botched because people don't understand
naming and why it matters in PKIX. You can leave yourself open to very
significant but trivial attacks. And then there's revocation.

All of the material we have on PKIX is in the wiki and it's as accurate as
we can make it. We just don't encourage it, and we don't exactly jump to
answer questions about it when it inevitably works differently than people
think.

-- Scott



More information about the users mailing list