Docusign SSO

Klingenstein, Nate nklingenstein at calstate.edu
Mon Nov 28 21:42:24 EST 2016


Asking the entity about itself (i.e., provide some text file over the
Internet with crypographic keys etc.) also provides zero trust, making
this approach rather pointless -- unless you have solved the problem
of entity owners hosting their own metadata /signed/ by a trusted
third party.

This is what TLS was intended to be, after all, and the entire Internet is strung
together with enough bogus certificates and flimsy trust to keep VeriSign's yacht
afloat.

That said, the point stands, and this actually is a secondary challenge: is
there any relationship between the TLS certificate and, if used, a metadata
signing certificate?
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20161129/713119c2/attachment-0001.html>


More information about the users mailing list