Digital-Identity-Labs / smee

SAML Metadata Entity Extractor (etc)
Apache License 2.0
0 stars 0 forks source link

webTLS certificate/signature verification? #31

Open binaryape opened 1 year ago

binaryape commented 1 year ago

Verify TLS endpoint Verify metadata cert is same as transport cert on metadata's source URL (!) or is signed by transport URL?

Case: metadata at a TLS endpoint, metadata is signed with that [that tls?] key pair. metadata signature is self-referential with a newly minted key, the only root of trust is webTLS