Signing metadata

Peter Schober peter.schober at univie.ac.at
Wed Jun 21 12:54:03 EDT 2017


* Larissa Riedel <larissa.riedel88 at gmail.com> [2017-06-21 18:20]:
> I'm aware of how metadata is usually created. I've also already used the
> XMLSecTool to sign metadata of an example federation.
> 
> The scenario consists of a single IdP and a single SP with both not being
> in a federation. I'm trying to distribute the metadata (automatically
> signed) in both directions via https.

How is trust established between those entities, then? By manually
exchanging and configuring certificates at each party (as part of a
signature validation filter)? By relying on PKIX and signing the
metadata with keys that have CA-signed certificates?

-peter


More information about the users mailing list