SP Requires Signed IdP Cert...

Cantor, Scott cantor.2 at osu.edu
Fri Jan 30 01:15:23 EST 2015


> Ok.  I think I know why that is.  OpenSAML is perfectly capable of emitting
> the whole cert chain represented in the credential, but the default config on
> the relevant KeyInfoGeneratorFactory doesn't actually do it.  We just emit
> the entity cert.  At the moment I can't think of any good reason not to
> change the default config to emit the whole cert chain.

If that applies to V3 as well, we should file an issue to get that changed.

-- Scott



More information about the users mailing list