Use signing key on HSM to sign assertions

Cantor, Scott cantor.2 at osu.edu
Mon May 7 10:44:46 EDT 2018


> HSM integration is limited to the proxy that way, and the client only sends
> the digest and receives the signed digest via JSON over HTTP.
> (Securing that HTTP connection is left to the deployer.)

Perhaps, but that's obviously a matter of changing fairly core code and would not be possible from a deployer point of view.

In theory, PKCS11 would be something that just works given a bit of additional code, but that's theory.

Xmlsectool doesn't use the OpenSAML APIs at all, so that's why it supporting PKCS11 doesn't directly translate into making the IdP work.

-- Scott



More information about the users mailing list