Uploaded image for project: 'PicketLink'
  1. PicketLink
  2. PLINK-80

SP KeyProvider required config

XMLWordPrintable

    • Icon: Feature Request Feature Request
    • Resolution: Done
    • Icon: Minor Minor
    • PLINK_2.7.0.Beta2
    • PLINK_2.7.0.Beta1
    • SAML
    • None

      When utilizing a KeyProvider for an SP only, the org.picketlink.identity.federation.core.impl.KeyStoreKeyManager.setAuthProperties() method is called. This method throws an exception if a SigningKeyPass isn't specified in the config.
      Why is this required if you aren't using the SAML2SignatureGenerationHandler?
      I only want to validate the returned IDP signature using the SAML2SignatureValidationHandler, so all I should need is the KeyStoreURL, KeyStorePass and the ValidatingAlias.
      Investigate whether or not the "SigningKeyPass" Auth param should be required if only using signature validation and not generation.

            psilva@redhat.com Pedro Igor Craveiro
            blawrence_jira Bobby Lawrence (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved: