Signing metadata
Peter Schober
peter.schober at univie.ac.at
Wed Jun 21 12:54:03 EDT 2017
* Larissa Riedel <larissa.riedel88 at gmail.com> [2017-06-21 18:20]:
> I'm aware of how metadata is usually created. I've also already used the
> XMLSecTool to sign metadata of an example federation.
>
> The scenario consists of a single IdP and a single SP with both not being
> in a federation. I'm trying to distribute the metadata (automatically
> signed) in both directions via https.
How is trust established between those entities, then? By manually
exchanging and configuring certificates at each party (as part of a
signature validation filter)? By relying on PKIX and signing the
metadata with keys that have CA-signed certificates?
-peter
More information about the users
mailing list