Separate KeyDescriptor for signing and encryption

Cantor, Scott cantor.2 at osu.edu
Fri Sep 25 12:24:01 EDT 2015


On 9/25/15, 12:03 PM, "users on behalf of Per Jørgen Vigdal" <users-bounces at shibboleth.net on behalf of Per.Jorgen.Vigdal at evry.com> wrote:

>Hello
>I am trying to configure a shibboleth SP . The IdP only accepts Separate KeyDescriptor for signing and encryption in the metadata provided by me,  although the certificate are to be equal .
>How can I achieve that ?

Alter your metadata accordingly? I'm not sure what the SP has to do with it.

Unless you're making the mistake of trying to supply generated metadata to a partner, which is not appropriate.

-- Scott



More information about the users mailing list