Skip to Content.
Sympa Menu

shibboleth-dev - Re: [Shibboleth-Announce] Shibboleth 2.0 SP Release Candidate 1

Subject: Shibboleth Developers

List archive

Re: [Shibboleth-Announce] Shibboleth 2.0 SP Release Candidate 1


Chronological Thread 
  • From: Ian Young <>
  • To:
  • Subject: Re: [Shibboleth-Announce] Shibboleth 2.0 SP Release Candidate 1
  • Date: Wed, 06 Feb 2008 16:11:31 +0000
  • Openpgp: id=EA2882BB

Scott Cantor wrote:

On the other hand an RRA administrator who has to approve the SP
definition inspects the callback URL/endpoings, he (hopefully) would get
suspicious and reject the definition.

So do that with the certificate submission. If you're claiming you need to
issue a certificate, what you're really claiming is you want an out of band
step. So add an out of band step. PoP in real time doesn't have to be that
step, and I don't think it can be, not without transport authentication.

We've been thinking in terms of phoning up the contact and confirming the certificate fingerprint with them.

Just FYI.

-- Ian



Archive powered by MHonArc 2.6.16.

Top of Page