Skip to Content.
Sympa Menu

shibboleth-dev - RE: Tomcat and certificate validation for SSL

Subject: Shibboleth Developers

List archive

RE: Tomcat and certificate validation for SSL


Chronological Thread 
  • From: "Scott Cantor" <>
  • To: <>
  • Cc: <>
  • Subject: RE: Tomcat and certificate validation for SSL
  • Date: Tue, 14 Jun 2005 17:05:14 -0400
  • Organization: The Ohio State University

> > There is no interoperable way to do the encryption
>
> what about just signing the Request then? and letting tls continue to
> handle the confidentiality? without client-auth, as the
> validation is done at the message level?

That's fine, but we still need replay detection. And what exactly have we
gained? Slowness? ;-)

-- Scott




Archive powered by MHonArc 2.6.16.

Top of Page