Relying party specific Credential and Metadata

Cantor, Scott cantor.2 at osu.edu
Thu Aug 29 16:44:49 EDT 2013


On 8/29/13 3:49 PM, "Sean McHugh" <sean8sean at gmail.com> wrote:

>I've obtained said cert, placed it and the private key in /credentials
>and modified the relying-party.xml configuration to utilize this cert for
>both signing and encryption
>with the relying party.

The IdP doesn't do any decryption, so that key has nothing to do with
encryption.

>- Do I also need to create a jks keystore as well?  Where is this
>referenced in the config?

No. IIRC the only reason it generates the keystore is for use with Tomcat
connectors.

>- When giving my IdP metadata to the new relying party, I assume that,
>considering all other aspects of my IdP are the same as for my other
>relying-parties, I can simply replace the inline
>x509 base64 text in my usual metadata info and give that to the
>relying-party

If nothing else is different, yes.

-- Scott




More information about the users mailing list