<div dir="ltr">Hi Peter,<div><div class="gmail_extra"><br></div></div><div class="gmail_extra"><div class="gmail_extra">> How is trust established between those entities, then? By manually</div><div class="gmail_extra">> exchanging and configuring certificates at each party (as part of a</div><div class="gmail_extra">> signature validation filter)? By relying on PKIX and signing the</div><div class="gmail_extra">> metadata with keys that have CA-signed certificates?</div></div><div class="gmail_extra"><br></div><div class="gmail_extra"><div class="gmail_extra">Yes trust is established by exchanging and configuring certificates at each party. </div><div class="gmail_extra">I understand that there is no real practical use for that scenario and that there would a lot overhead included if used in that way. The sole reason for this scenario was to describe a very minimalistic example of how trust is established with shibboleth.</div><div><br></div><div>Larissa</div></div></div>