restrict xmlsec1 from using public keys
Yitzchak Scott-Thoennes <[email protected]> Wed, 28 Oct 2015 11:27:35 -0700
| Newsgroups | gmane.text.xml.xmlsec |
|---|---|
| Message-ID | <CABsMtmVBjynUiQ7icLfdWv17z4Anir4RtypE72WCUfM4qZk_Xw@mail.gmail.com> |
I'm using the xmlsec1 tool like: xmlsec1 --verify --trusted-pem cert.pem --id-attr:ID urn:oasis:names:tc:SAML:2.0:assertion:Assertion signedassertion.xml where cert.pem is the public key for a self-signed cert that I expect to have been used to sign the my assertion. But it's my understanding that that xmlsec1 call would in fact succeed if it was signed with some other certificate that my system trusts. Is there a way to prevent that? Thanks _______________________________________________ xmlsec mailing list [email protected] http://www.aleksey.com/mailman/listinfo/xmlsec