Native ADFS support and signature verification

Robert Lowe robertmlowe at rmlowe.com
Tue Sep 19 09:22:19 EDT 2017


> The default trust engine chain is ExplicitKey followed by PKIX, so
> whereever you read "doesn't use PKIX by default", it's wrong.
>

What exactly causes it to move along the chain? Would it only do that if it
thinks there's no explicit key configured (i.e. a metadata problem as Rod
suggests)?

-- 
Best regards,

Robert Lowe
http://crepuscular.rmlowe.com/
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170919/e84011e5/attachment-0001.html>


More information about the users mailing list