WIF config: issuerNameRegistry vs. certificateValidation

后端 未结 1 1133
Happy的楠姐
Happy的楠姐 2021-01-03 17:06

In the Windows Identity Foundation (WIF) 4.5 config, what is the relationship between issuerNameRegistry and certificateValidation? What portion of

相关标签:
1条回答
  • 2021-01-03 17:06

    IssuerNameRegistry is a lookup table from Thumbprint to EntityID. Only Issuers in that table will be trusted.

    CertificateValidationMode is additional on top of the table requirement. "None" is almost always the best setting. Because the trust is setup through metadata, normally not through chain trust to a CA. So ChainBuilding, CRL etc. is not relevant.

    0 讨论(0)
提交回复
热议问题