using a cert bundle in a TrustEngine
Liam Hoekenga
liamr at umich.edu
Fri Jan 31 10:45:03 EST 2014
On Fri, Jan 31, 2014 at 10:17 AM, Peter Schober
<peter.schober at univie.ac.at>wrote:
> Once you've establshed the authenticity of that key you'd just use it
> like a self-signed one, i.e., put in in (unsigned, locally-managed)
> metadata and be done with it.
>
Showing my ignorance... I guess I'm not clear on when I need to define
TrustEngines.
I'm reading through the IdP TrustEngine documentation in the wiki.
I've used "StaticExplicitKeySignature" TrustEngines to validate signed
federation metadata (InCommon, our campus fed, etc).
I /thought/ that I needed to define a TrustEngine if the SP was going to
send signed and / or encrypted assertions to our IdP.
Is that functionality based strictly on the certs in the metadata? (from
the docs - "If a key with either no usage indicator, or a signing usage
indicator, is the credential provide by the peer then it is trusted.")
Liam
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20140131/6a1efa95/attachment.html
More information about the users
mailing list