Native ADFS support and signature verification

Cantor, Scott cantor.2 at osu.edu
Tue Sep 19 08:34:06 EDT 2017


On 9/19/17, 8:16 AM, "users on behalf of Robert Lowe" <users-bounces at shibboleth.net on behalf of robertmlowe at rmlowe.com> wrote:

> This seems to imply that PKIX is being used, however I understood that Shibboleth doesn't use PKIX by default and we haven't
> explicitly configured any TrustEngines. Is this not the case when using the ADFS support?

The default trust engine chain is ExplicitKey followed by PKIX, so whereever you read "doesn't use PKIX by default", it's wrong.

-- Scott





More information about the users mailing list