sp(2.5.5) <-> idp(3.1.2) and ecdsa certs

Cantor, Scott cantor.2 at osu.edu
Tue Oct 20 12:44:26 EDT 2015


On 10/20/15, 12:27 PM, "users on behalf of Jarno Huuskonen" <users-bounces at shibboleth.net on behalf of jarno.huuskonen at uef.fi> wrote:
>
>I can also sign the same metadata with xmlsectool.sh (key/cert in
>keystore):
>xmlsectool.sh --sign --inFile unsigned.xml \
>--referenceIdAttributeName ID \
>--digest sha-384 --keystore keystore.jks --keyPassword changeit \
>--keystoreType jks --key uef_metadata --outFile signed.xml

Does the SP accept that?

xmlsec from Aleksey and my version are at least both using OpenSSL, so if there's an issue with those routines, or a common bug we both made, that wouldn't show.

>And I can verify both xmlsectool.sh and xmlsec1 signed metadata with:
>xmlsec1 and xmlsectool.sh

Hmm. Hopefully Brent just tweaked something and a POST from the IdP actually does work. Otherwise this is getting pretty weird.

-- Scott



More information about the users mailing list