<div dir="ltr"><div class="gmail_extra"><br><div class="gmail_quote">On Fri, Jan 31, 2014 at 10:17 AM, Peter Schober <span dir="ltr"><<a href="mailto:peter.schober@univie.ac.at" target="_blank">peter.schober@univie.ac.at</a>></span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-color:rgb(204,204,204);border-left-style:solid;padding-left:1ex"><div id=":1y3" style="overflow:hidden">Once you've establshed the authenticity of that key you'd just use it<br>
like a self-signed one, i.e., put in in (unsigned, locally-managed)<br>
metadata and be done with it.</div></blockquote></div><div class="gmail_extra"><br></div>Showing my ignorance... I guess I'm not clear on when I need to define TrustEngines.</div><div class="gmail_extra">I'm reading through the IdP TrustEngine documentation in the wiki.</div>
<div class="gmail_extra"><br></div><div class="gmail_extra">I've used "StaticExplicitKeySignature" TrustEngines to validate signed federation metadata (InCommon, our campus fed, etc).</div>
<div class="gmail_extra"><br></div><div class="gmail_extra">I /thought/ that I needed to define a TrustEngine if the SP was going to send signed and / or encrypted assertions to our IdP.</div><div class="gmail_extra">Is that functionality based strictly on the certs in the metadata? (from the docs - "<span style="color:rgb(51,51,51);font-family:Arial,Helvetica,FreeSans,sans-serif;font-size:13px;line-height:17.33333396911621px">If a key with either no usage indicator, or a signing usage indicator, is the credential provide by the peer then it is trusted.")</span></div>
<div class="gmail_extra"><br></div><div class="gmail_extra">Liam</div><div class="gmail_extra"><br></div></div>