using a cert bundle in a TrustEngine
Liam Hoekenga
liamr at umich.edu
Fri Jan 31 10:05:22 EST 2014
On Thu, Jan 30, 2014 at 9:35 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:
> Whatever the SP is asking about, it has nothing to do with a TrustEngine.
> That has nothing to do with what somebody else receives.
>
We're talking about front channel stuff.
The SP in question is NetIQ (Novell) AccessManager.
Their metadata includes separate KeyDescriptors for signing (using a
certificate signed by a verisign CA through two layers of intermediaries)
and encryption (signed by a CA internal to their novell infrastructure).
Don't we need to set up TrustEngines for validation if they're going to
sign or encrypt their assertions?
Liam
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20140131/70ce98b2/attachment-0001.html
More information about the users
mailing list