Signing metadata
Larissa Riedel
larissa.riedel88 at gmail.com
Wed Jun 21 13:36:13 EDT 2017
Hi Peter,
> How is trust established between those entities, then? By manually
> exchanging and configuring certificates at each party (as part of a
> signature validation filter)? By relying on PKIX and signing the
> metadata with keys that have CA-signed certificates?
Yes trust is established by exchanging and configuring certificates at each
party.
I understand that there is no real practical use for that scenario and that
there would a lot overhead included if used in that way. The sole reason
for this scenario was to describe a very minimalistic example of how trust
is established with shibboleth.
Larissa
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170621/b9a61d50/attachment.html>
More information about the users
mailing list