Skip to Content.
Sympa Menu

shibboleth-dev - Re: Follow-up to design call re: path length

Subject: Shibboleth Developers

List archive

Re: Follow-up to design call re: path length


Chronological Thread 
  • From: Jim Fox <>
  • To: Scott Cantor <>
  • Cc:
  • Subject: Re: Follow-up to design call re: path length
  • Date: Tue, 1 Mar 2005 10:07:15 -0800 (PST)


I think Howard would agree, but that's also (I think) why he's arguing for
anything we build as a one-off that's not PKIX to be limited to one hop.
Either you're doing 3280 and your head probably explodes, or you're doing
something else, and doing chains at that point is probably overkill.


FWIW, we at UW could get by just fine with the "MetaData Alone"
implementation, and just bag all the CA stuff.

Any SP wanting any useful information will have to register with
us anyway. We can get its public key then. If it uses a cert
from our own CA then we already have the key. We already implement
pubcookie this way.

Jim





Archive powered by MHonArc 2.6.16.

Top of Page