Re: STS with X.509 based authentication: How does proof-of-possession work?

2015-02-22 Thread Frizz
> http://owulff.blogspot.de/2012/02/saml-tokens-and-ws-trust-security-token.html > . > > Regards, > Andrei. > > > -Original Message- > > From: Frizz [mailto:frizzthe...@googlemail.com] > > Sent: Sonntag, 22. Februar 2015 09:39 > > To: users@cxf.apache.

RE: STS with X.509 based authentication: How does proof-of-possession work?

2015-02-22 Thread Andrei Shakirin
STS with X.509 based authentication: How does proof-of-possession > work? > > I'd like to use CXF STS in an X.509 authentication based scenario. What I > don't > understand right now is how it does proof-of-possession. I mean anyone can > present a certificate to the STS -

STS with X.509 based authentication: How does proof-of-possession work?

2015-02-22 Thread Frizz
I'd like to use CXF STS in an X.509 authentication based scenario. What I don't understand right now is how it does proof-of-possession. I mean anyone can present a certificate to the STS - it does not mean that she has the private key. How does this work in CXF?