No need for cert exchange between SP and IdP?

Paul Hethmon paul.hethmon at clareitysecurity.com
Fri Jul 27 11:14:20 EDT 2012


Correct. The necessary public keys are in the metadata files for each
respectively.

Paul

On 7/27/12 11:11 AM, "Andrew Webb" <andrew.webb at statpro.com> wrote:

>Shib SP signs authn requests with its cert's private key, and IdPs check
>this
>signature using the X509 public key that it reads from the SP's metadata.
>Is that right?  Ergo SP and IdP only have to exchange metadata documents,
>and do not need to exchange cert files.  Is that correct?
>
>
>
>
>--
>View this message in context:
>http://shibboleth.1660669.n2.nabble.com/No-need-for-cert-exchange-between-
>SP-and-IdP-tp7580952.html
>Sent from the Shibboleth - Users mailing list archive at Nabble.com.
>--
>To unsubscribe from this list send an email to
>users-unsubscribe at shibboleth.net



More information about the users mailing list