No need for cert exchange between SP and IdP?

Andrew Webb andrew.webb at statpro.com
Fri Jul 27 11:11:50 EDT 2012


Shib SP signs authn requests with its cert's private key, and IdPs check this
signature using the X509 public key that it reads from the SP's metadata. 
Is that right?  Ergo SP and IdP only have to exchange metadata documents,
and do not need to exchange cert files.  Is that correct?




--
View this message in context: http://shibboleth.1660669.n2.nabble.com/No-need-for-cert-exchange-between-SP-and-IdP-tp7580952.html
Sent from the Shibboleth - Users mailing list archive at Nabble.com.


More information about the users mailing list