Re-instate metadata signing for connector in TEST, SC-2670

This commit is contained in:
Patrik Holmqvist 2025-03-25 09:50:22 +01:00
parent 802e95c3f8
commit 226957e4e0
Signed by: pahol
GPG key ID: 5D5B0D4E93F77273
2 changed files with 13 additions and 2 deletions

View file

@ -125,7 +125,6 @@ saml:
backup-location: ${connector.backup-directory}/metadata/sc-cache.xml
validation-certificate: file:${CONNECTOR_DIRECTORY}/credentials/sc-qa-md-signer.crt
credentials:
# Use same as for IdP except for the metadata signing credential
sign:
bundle: connector-sign
encrypt:

View file

@ -86,6 +86,14 @@ credential:
alias: sc_eidas_encrypt
key-password: ${PKCS11_PIN}
monitor: true
connector-hsm-md-sign:
name: "Connector HSM Metadata Signing Credential"
store-reference: pkcs11-store
key:
#certificates: file:${CONNECTOR_DIRECTORY}/credentials/sctest2.crt
alias: sctest2
key-password: ${PKCS11_PIN}
monitor: true
#pem:
#oauth2:
# TODO: Fix certs
@ -104,6 +112,11 @@ connector:
eu-metadata:
location: https://<%= @environment %>.md.eidas.swedenconnect.se/role/idp.xml
validation-certificate: file:${CONNECTOR_DIRECTORY}/credentials/sc-<%= @environment %>-md-signer.crt
eidas:
credentials:
# Use same as for IdP except for the metadata signing credential
metadata-sign:
bundle: connector-hsm-md-sign
prid:
policy-resource: file:${CONNECTOR_DIRECTORY}/prid/policy.properties
idp:
@ -140,7 +153,6 @@ saml:
backup-location: ${connector.backup-directory}/metadata/sc-cache.xml
validation-certificate: file:${CONNECTOR_DIRECTORY}/credentials/sc-<%= @environment %>-md-signer.crt
credentials:
# Use same as for IdP except for the metadata signing credential
sign:
bundle: connector-sign
encrypt: