shibboleth-dev - RE: Encryption key strategies
Subject: Shibboleth Developers
List archive
- From: "Scott Cantor" <>
- To: <>
- Subject: RE: Encryption key strategies
- Date: Thu, 22 Jun 2006 12:56:24 -0400
- Organization: The Ohio State University
> Is the obvious answer, to store the peer's certificate in the
> metadata, somehow not feasible?
It's not only feasible, it's to my best guess the only thing that most of
the products probably support (although they really import the metadata into
local store, and allow you to manipulate the peer's cert(s) in that form
also).
That's not my question.
It's what else, if anything, are people expecting? And if the answer's
nothing, then I'm simply pointing out that all the current (slight) benefits
of key indirection on the signing side are lost, so it's likely that the
long term implication is we end up encouraging federations to dump the CA
approach.
I'm just highlighting the bigger picture. We could have just gone off and
done it as we build, but the whole point of the list I assume is so people
can see what's happening more transparently and raise their hands when they
object.
-- Scott
- Re: Encryption key strategies, (continued)
- Re: Encryption key strategies, Chad La Joie, 06/22/2006
- Re: Encryption key strategies, Tom Scavo, 06/22/2006
- Re: Encryption key strategies, Chad La Joie, 06/22/2006
- Re: Encryption key strategies, Tom Scavo, 06/22/2006
- Re: Encryption key strategies, Chad La Joie, 06/22/2006
- Re: Encryption key strategies, Tom Scavo, 06/22/2006
- RE: Encryption key strategies, Scott Cantor, 06/22/2006
- Re: Encryption key strategies, Tom Scavo, 06/22/2006
- RE: Encryption key strategies, Scott Cantor, 06/22/2006
- RE: Encryption key strategies, Jim Fox, 06/22/2006
- RE: Encryption key strategies, Scott Cantor, 06/22/2006
- Re: Encryption key strategies, Keith Hazelton, 06/22/2006
- Re: Encryption key strategies, Chad La Joie, 06/22/2006
- Re: Encryption key strategies, Tom Scavo, 06/22/2006
- RE: Encryption key strategies, Scott Cantor, 06/22/2006
- Re: Encryption key strategies, Reimer Karlsen-Masur, DFN-CERT, 06/23/2006
- RE: Encryption key strategies, Scott Cantor, 06/23/2006
- Re: Encryption key strategies, Ian Young, 06/28/2006
- Re: Encryption key strategies, Tom Scavo, 06/22/2006
- Re: Encryption key strategies, Chad La Joie, 06/22/2006
- Re: Encryption key strategies, Alistair Young, 06/26/2006
- RE: Encryption key strategies, Scott Cantor, 06/26/2006
Archive powered by MHonArc 2.6.16.