Sibboleth SP v3.x Metadata Signature validation using PKIX trust engine question

Cantor, Scott cantor.2 at osu.edu
Fri Nov 10 16:48:51 UTC 2023


Specifying the name is obviously required, otherwise you'd have no security whatsoever. This isn't TLS, the name can't really come from anywhere else other than the configuration. That's the only thing that designates the actual signer.

> It appears that the signing certificate must be explicitly whitelisted and that
> it being issued by a trusted CA is not enough. 

That is not the case if it's configured properly and the necessary intermediates are available to build the path.

-- Scott




More information about the users mailing list