No need for cert exchange between SP and IdP?

Kevin P. Foote kpfoote at iup.edu
Fri Jul 27 11:13:45 EDT 2012


Metadata is the commodity of exchange yes.

------
thanks
  kevin.foote

On Fri, 27 Jul 2012, Andrew Webb wrote:

-> Shib SP signs authn requests with its cert's private key, and IdPs check this
-> signature using the X509 public key that it reads from the SP's metadata. 
-> Is that right?  Ergo SP and IdP only have to exchange metadata documents,
-> and do not need to exchange cert files.  Is that correct?
-> 
-> 
-> 
-> 
-> --
-> View this message in context: http://shibboleth.1660669.n2.nabble.com/No-need-for-cert-exchange-between-SP-and-IdP-tp7580952.html
-> Sent from the Shibboleth - Users mailing list archive at Nabble.com.
-> --
-> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
-> 


More information about the users mailing list