Extensibility of SAML 2 metadata

Keith Hazelton hazelton at wisc.edu
Wed Jun 20 13:10:49 BST 2012


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

The Bamboo use case is not about browser-facing SSL/TLS, but about one entity performing client AuthN when accessing another. I will note that this scenario is not SAML related, so maybe the answer is it doesn't belong in SAML metadata, extensions or not.

        --Keith
_______________
On Jun 20, 2012, at 07:06:02, Tom Scavo wrote:

> On Wed, Jun 20, 2012 at 7:53 AM, Keith Hazelton <hazelton at wisc.edu> wrote:
>> 
>> On the question of certs in SAML metadata for client authN over SSL, looking
>> for guidance on how to do that.  I see this page:
>> 
>> https://spaces.internet2.edu/display/InCCollaborate/X.509+Certificates+in+Metadata
> 
> That page is probably not what you're looking for. It (and its child
> pages) emphasize that "certificates in metadata...are not used for
> browser-facing SSL/TLS transactions on port 443."
> 
> Tom
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net

-----BEGIN PGP SIGNATURE-----
Version: GnuPG/MacGPG2 v2.0.18 (Darwin)
Comment: GPGTools - http://gpgtools.org

iQEcBAEBAgAGBQJP4b3JAAoJEPXbVHOlscTv/gcIALbOnzUzwbOAlm5h9Pfw6HK0
2ribow76e7o4LdhCKfAy857owwMvpCpNJ6o9dl0cdYCmZlHfm2kk82wus8Gm05ek
b7LsYlXPOE/WgkRsxbRAemNAhmgZlLFOd2RD0EgldKersonDfXfQax8/z1KFH1ik
SP6Mt28wEPdSVRbWUZnxBlh8IGrHyCtKN18D7773suVepCYIEjmIWMAugI3PjlyR
J+afWZe7qfRiRDG5VhmPlcCdPy8F5aAk4Q0i8MOxMsMhr1puAOBnqKC72fJGDo57
tnE+Q/L8rne5Sd9HdMecoZojnR8NO4rHVxB/nwVhLuljK3g9O5k6dd/vQh/yBGQ=
=BMuI
-----END PGP SIGNATURE-----


More information about the users mailing list