Use signing key on HSM to sign assertions

Cantor, Scott cantor.2 at osu.edu
Thu May 10 20:01:54 EDT 2018


>   * If I configure Shibboleth to neither sign the assertions or  the response, can I
> inject my document signer implementation as an outbound interceptor (as
> mentioned here:
> https://wiki.shibboleth.net/confluence/display/IDP30/ProfileHandling#Profile
> Handling-OutboundInterceptContract).

Conceptually I suppose. That would certainly be an interesting workaround.

> If this is so, it there an example of an outbound interceptor ? I can only find
> examples of inbound and post authentication interceptors in the Shibboleth
> code.

There is no difference, all interceptors are the same, just webflows.

-- Scott



More information about the users mailing list