Use signing key on HSM to sign assertions

Peter Schober peter.schober at univie.ac.at
Tue May 8 06:56:01 EDT 2018


Ian,

Thanks for your explanations.

* Ian Young <ian at iay.org.uk> [2018-05-08 12:33]:
> Again, if pyeleven provides an actual native PKCS#11 library, all of
> our products could in principle talk to it through the
> bridge.

Just to clarify: pyeleven's whole raison d'être is avoiding the need
for native PKCS#11 support in applications.

So clearly the IDP (or XmlSecTool, or Java as a platform) is not a
suitable target for a pyeleven client (unless someone wrote some stub
code that only did JSON-over-HTTP in the backend).
Forget I ever mentioned it. ;)

-peter


More information about the users mailing list