Skip to Content.
Sympa Menu

shibboleth-dev - RE: [Shib-Dev] how to deliver personal infocard keyinfo to app?

Subject: Shibboleth Developers

List archive

RE: [Shib-Dev] how to deliver personal infocard keyinfo to app?


Chronological Thread 
  • From: "Scott Cantor" <>
  • To: <>
  • Subject: RE: [Shib-Dev] how to deliver personal infocard keyinfo to app?
  • Date: Mon, 11 Aug 2008 00:21:55 -0400
  • Organization: The Ohio State University

> My thinking is that the PPID has the security of a big random number,
> which cannot be guessed. It can only be compromised if the application
> gives it away. It can be protected by keeping it secret.

I suppose, but nothing prevents anything from asserting that PPID if it is
known, so I don't see why I'd trust such a system.

> How about a base64 of an sha1 of the modulus? That's a mathematical
> thing. All languages ought to do it about the same.

I don't know enough about the RSA algorithm, but I was under the impression
only the two numbers were unique, not just the modulus. That's why I was
trying for a known key format, rather than trying to invent some way to hash
multiple numbers and accidentally screw it up.

- Scott





Archive powered by MHonArc 2.6.16.

Top of Page