Include RSAKeyValue In Assertions in IDP v3

Doug Holmes doug.holmes.42 at gmail.com
Tue Nov 8 09:38:18 EST 2016


Back in June, there was a question:

> With a v2 IdP, is it possible to have the IdP include an RSAKeyValue
> element in the XML signature in addition to the X509Data element?

Brent Putman replied:

"Yes.  As Scott said though, it is a global change, so be aware. You'll
be doing this for all SPs.  Most shouldn't care, so just FYI.   (In v3,
you can customize things like this on a per-SP basis if desired)."

I am using Shibboleth v3 and I'm looking for exactly that customization, to
create the RSAKeyValue element in the Signature block for a particular SP.
I cannot find any example online for this and I'm not familiar enough with
the source code to determine how it might be configured.

Does anyone have an example of how to configure this in v3 - adding the
KeyValue/RSAKeyValue information to the KeyInfo element in the Signature?

TIA
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20161108/ffc2c72c/attachment-0001.html>


More information about the users mailing list