Including keyName in keyInfo

Cantor, Scott cantor.2 at osu.edu
Wed Apr 17 10:13:32 EDT 2013


On 4/17/13 6:34 AM, "Matheesha Weerasinghe" <matheesha at gmail.com> wrote:

>Hi
> 
>Is it possible to configure Shibboleth IDP such that when it generates a
>signed SAML response, it includes keyName with say the thumbprint of the
>cert?

The schema for the Credential element in the relying-party config appears
to support a KeyName element. My speculation would be that might cause it
to be inserted.

I actually thought we did include key names generated from a certificate
already.

-- Scott




More information about the users mailing list