When is PrivateKey password used?

avalanche333 Matthew.R.Zmuda at td.com
Tue Jun 11 19:55:56 EDT 2013


I've had a password set there all along on v 2.3.1 of idp.
Never and an issue. However today I mistakenly put the wrong password and things still worked which had me concerned.
However I actually though the purpose of this password was to allow you to sign/encrypt SAML messages using the private key. From what I am hearing that is not the case.

Matt Zmuda | IT Solutions Developer
DCTS Online Channels - Authentication and Security - CIP/ESR

From: Brent Putman [via Shibboleth] [mailto:ml-node+s1660669n7587458h48 at n2.nabble.com]
Sent: Tuesday, June 11, 2013 4:47 PM
To: Zmuda, Matthew R
Subject: Re: When is PrivateKey password used?


On 6/11/13 1:37 PM, Zmuda, Matthew R wrote:

>
> Looking at the IdPCredentials docs -
> https://wiki.shibboleth.net/confluence/display/SHIB2/IdPCredentials
>
>
>
> PrivateKey - The private key file for the credential; only one
> PrivateKey element is allowed. The PrivateKey element may include a
> password attribute with the decryption password for the key.
>
>
>

I was actually just reviewing the XML schema for the config above. Turns
out the docs above are not consistent with the schema.  I don't know
why, but in July 2008 (shib-common r766)  the support for the password
attribute was removed in the schema.  What is now documented would
actually be schema-invalid.

Given that this was done (I believe) after v2 was released and that it
is a breaking change, I think this was a mistake.  Although since it's
gone nearly 5 years without anyone hitting it, I assume nobody actually
tries to use the password attribute on a PrivateKey.   :-)

I guess we'll discuss whether to put the support back in the schema, or
just leave it and fix the docs.  The config parsing code seems to still
have the password support, so at first glance it just appears to be the
schema that was messed up.

--Brent




--
To unsubscribe from this list send an email to [hidden email]</user/SendEmail.jtp?type=node&node=7587458&i=0>

________________________________
If you reply to this email, your message will be added to the discussion below:
http://shibboleth.1660669.n2.nabble.com/When-is-PrivateKey-password-used-tp7587443p7587458.html
To unsubscribe from When is PrivateKey password used?, click here<http://shibboleth.1660669.n2.nabble.com/template/NamlServlet.jtp?macro=unsubscribe_by_code&node=7587443&code=TWF0dGhldy5SLlptdWRhQHRkLmNvbXw3NTg3NDQzfDEzMzE1MTYwODQ=>.
NAML<http://shibboleth.1660669.n2.nabble.com/template/NamlServlet.jtp?macro=macro_viewer&id=instant_html%21nabble%3Aemail.naml&base=nabble.naml.namespaces.BasicNamespace-nabble.view.web.template.NabbleNamespace-nabble.view.web.template.NodeNamespace&breadcrumbs=notify_subscribers%21nabble%3Aemail.naml-instant_emails%21nabble%3Aemail.naml-send_instant_email%21nabble%3Aemail.naml>

NOTICE: Confidential message which may be privileged. Unauthorized use/disclosure prohibited. If received in error, please go to www.td.com/legal for instructions.
AVIS : Message confidentiel dont le contenu peut être privilégié. Utilisation/divulgation interdites sans permission. Si reçu par erreur, prière d'aller au www.td.com/francais/avis_juridique pour des instructions.




--
View this message in context: http://shibboleth.1660669.n2.nabble.com/When-is-PrivateKey-password-used-tp7587443p7587463.html
Sent from the Shibboleth - Users mailing list archive at Nabble.com.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130611/96b6e333/attachment.html 


More information about the users mailing list