You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 5 Next »

KeyDescriptor

The KeyDescriptor stores a certificate, BUT the only interesting part are the public-key stored inside the certificate! The private part of the key is stored on the machine responsible for the Entity,

Some SAML implementations also looks at the notValidAfter value and refuses to use old certificates/keys

There are two types of keys/certificates used in the Metadata for an entity. 

KeyDescriptor use="encryption"

Stores the public encryption key. Data sent TO the Entity could be encrypted with this key and the only decrypted by the Entity is self.



Gamla sidor 

Sidor att plocka ifrån

  • No labels