SP Requires Signed IdP Cert...

Brent Putman putmanb at georgetown.edu
Fri Jan 30 16:14:23 EST 2015


On 1/30/15 1:15 AM, Cantor, Scott wrote:
>> Ok.  I think I know why that is.  OpenSAML is perfectly capable of emitting
>> the whole cert chain represented in the credential, but the default config on
>> the relevant KeyInfoGeneratorFactory doesn't actually do it.  We just emit
>> the entity cert.  At the moment I can't think of any good reason not to
>> change the default config to emit the whole cert chain.
> If that applies to V3 as well, we should file an issue to get that changed.

Yes, it does, I'll take care of it.


More information about the users mailing list