using a cert bundle in a TrustEngine

Liam Hoekenga liamr at umich.edu
Fri Jan 31 10:05:22 EST 2014


On Thu, Jan 30, 2014 at 9:35 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:

> Whatever the SP is asking about, it has nothing to do with a TrustEngine.
> That has nothing to do with what somebody else receives.
>

We're talking about front channel stuff.
The SP in question is NetIQ (Novell) AccessManager.

Their metadata includes separate KeyDescriptors for signing (using a
certificate signed by a verisign CA through two layers of intermediaries)
and encryption (signed by a CA internal to their novell infrastructure).

Don't we need to set up TrustEngines for validation if they're going to
sign or encrypt their assertions?

Liam
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20140131/70ce98b2/attachment-0001.html 


More information about the users mailing list