shibboleth-dev - RE: semantics of metadata signing certificate
Subject: Shibboleth Developers
List archive
- From: "Scott Cantor" <>
- To: <>
- Subject: RE: semantics of metadata signing certificate
- Date: Fri, 28 Jul 2006 00:22:50 -0400
- Organization: The Ohio State University
> The code for evaluating signed objects isn't used by the 1.x.x IdP.
> It was added for the original stalled Java SP development. Some
> variation of it will be used in the 2.0 IdP, though.
This isn't 100% true in the sense that it was in part added to support SAML
artifact lookup using signed requests from SAML products, and I had to use
that at Catalyst with some people that couldn't do TLS.
So, the code is functional for artifact requests, but not for attribute
queries (the authentication processing was more complex there and I didn't
want to screw anything up for Shibboleth changing it).
> I agree. I'd really like to dump the useless baggage here. The dsig
> XML format of RSA keys is a total pain for regular humans,
> unfortunately. Heck, if we can get acceptable performance using
> encryption, I'd just as soon use pgp keys.
I think the XMLSig syntax for PGP may be worse...
-- Scott
- semantics of metadata signing certificate, Ian Young, 07/24/2006
- RE: semantics of metadata signing certificate, Scott Cantor, 07/24/2006
- Re: semantics of metadata signing certificate, Ian Young, 07/27/2006
- RE: semantics of metadata signing certificate, Scott Cantor, 07/27/2006
- Re: semantics of metadata signing certificate, Ian Young, 07/27/2006
- RE: semantics of metadata signing certificate, Scott Cantor, 07/27/2006
- Re: semantics of metadata signing certificate, Walter Hoehn, 07/27/2006
- RE: semantics of metadata signing certificate, Scott Cantor, 07/28/2006
- Re: semantics of metadata signing certificate, Ian Young, 07/27/2006
- RE: semantics of metadata signing certificate, Scott Cantor, 07/27/2006
- Re: semantics of metadata signing certificate, Ian Young, 07/27/2006
- RE: semantics of metadata signing certificate, Scott Cantor, 07/24/2006
Archive powered by MHonArc 2.6.16.