Back-Channel Attribute Authority

Cantor, Scott cantor.2 at osu.edu
Fri Jul 12 11:28:15 EDT 2013


On 7/12/13 10:55 AM, "Joshua Riffle" <jriffle at apu.edu> wrote:

>I see what you mean. Is it assumed that the self-signed certificate on
>the attribute authority endpoints matches the one in the IDP's metadata?
>Or likewise should they be different for security reasons?

It must be in the metadata.

It's a personal choice, but no, they're almost never different in practice.

-- Scott




More information about the users mailing list