default IdP metadata for Shib IdP V3
Cantor, Scott
cantor.2 at osu.edu
Wed Jan 20 12:59:54 EST 2016
On 1/20/16, 12:32 PM, "users on behalf of Eric Goodman" <users-bounces at shibboleth.net on behalf of Eric.Goodman at ucop.edu> wrote:
>
>Not to get too off topic here (probably too late) but I haven't generally heard recommendations for separation of Signature and Encryption keys presuming we're talking about the inverse operations on similar messages (so technically my messages signature and *de*cryption keys being the same). Just as a simple example, most PGP use cases I'm aware of use just the one key for both operations.
Well, use of subkeys for the individual operations seems to be the best practice, modulo that the people vocal about best practice tend to be the ones who are the most rigorous about things. But that partly seems to have to do with, again, a desire to separate the lifetimes of those keys, so it's back to key management.
-- Scott
More information about the users
mailing list