Signing metadata

Larissa Riedel larissa.riedel88 at gmail.com
Wed Jun 21 13:36:13 EDT 2017


Hi Peter,

> How is trust established between those entities, then? By manually
> exchanging and configuring certificates at each party (as part of a
> signature validation filter)? By relying on PKIX and signing the
> metadata with keys that have CA-signed certificates?

Yes trust is established by exchanging and configuring certificates at each
party.
I understand that there is no real practical use for that scenario and that
there would a lot overhead included if used in that way. The sole reason
for this scenario was to describe a very minimalistic example of how trust
is established with shibboleth.

Larissa
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170621/b9a61d50/attachment.html>


More information about the users mailing list