using a cert bundle in a TrustEngine

Liam Hoekenga liamr at umich.edu
Fri Jan 31 10:45:03 EST 2014


On Fri, Jan 31, 2014 at 10:17 AM, Peter Schober
<peter.schober at univie.ac.at>wrote:

> Once you've establshed the authenticity of that key you'd just use it
> like a self-signed one, i.e., put in in (unsigned, locally-managed)
> metadata and be done with it.
>

Showing my ignorance... I guess I'm not clear on when I need to define
TrustEngines.
I'm reading through the IdP TrustEngine documentation in the wiki.

I've used "StaticExplicitKeySignature" TrustEngines to validate signed
federation metadata (InCommon, our campus fed, etc).

I /thought/ that I needed to define a TrustEngine if the SP was going to
send signed and / or encrypted assertions to our IdP.
Is that functionality based strictly on the certs in the metadata?  (from
the docs - "If a key with either no usage indicator, or a signing usage
indicator, is the credential provide by the peer then it is trusted.")

Liam
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20140131/6a1efa95/attachment.html 


More information about the users mailing list