Trust Engine shibboleth

samir el otmani elotmani.samir at gmail.com
Tue Jan 13 10:13:33 EST 2015


can anyone explain me why we add this code into relaying-party.xml

 <!-- Trust engine used to evaluate the signature on loaded metadata. -->
     <security:TrustEngine id="shibboleth.MetadataTrustEngine"
xsi:type="security:StaticExplicitKeySignature">

      <security:Credential id="TestCredentials"
xsi:type="security:X509Filesystem">
        <security:Certificate>/opt/shibboleth-idp/credentials/federation.crt</security:Certificate>
      </security:Credential>
     </security:TrustEngine>

if we can access the metadata by simple URL like this one :
https://federation.renater.fr/test/renater-test-metadata.xml

what is the utility to verify the signature on loaded metadata .

thank you
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20150113/fdcc5b04/attachment.html 


More information about the users mailing list