Relying party specific Credential and Metadata
Cantor, Scott
cantor.2 at osu.edu
Thu Aug 29 16:44:49 EDT 2013
On 8/29/13 3:49 PM, "Sean McHugh" <sean8sean at gmail.com> wrote:
>I've obtained said cert, placed it and the private key in /credentials
>and modified the relying-party.xml configuration to utilize this cert for
>both signing and encryption
>with the relying party.
The IdP doesn't do any decryption, so that key has nothing to do with
encryption.
>- Do I also need to create a jks keystore as well? Where is this
>referenced in the config?
No. IIRC the only reason it generates the keystore is for use with Tomcat
connectors.
>- When giving my IdP metadata to the new relying party, I assume that,
>considering all other aspects of my IdP are the same as for my other
>relying-parties, I can simply replace the inline
>x509 base64 text in my usual metadata info and give that to the
>relying-party
If nothing else is different, yes.
-- Scott
More information about the users
mailing list