[JIRA] (IDP-1757) Generate sp-metadata.xml on install

Chris.Phillips@canarie.ca (Jira) jira at shibboleth.atlassian.net
Mon Aug 23 14:46:10 UTC 2021


Chris.Phillips at canarie.ca ( https://shibboleth.atlassian.net/secure/ViewProfile.jspa?accountId=557058%3Ad9c5b0aa-4ee5-45bd-b913-57fd7ee7e854 ) *commented* on IDP-1757 ( https://shibboleth.atlassian.net/browse/IDP-1757?atlOrigin=eyJpIjoiYzgyYTZmMzJmYjU1NGVkMjljZTUzNzcxNWE1YzMwMWIiLCJwIjoiaiJ9 )

Re: Generate sp-metadata.xml on install ( https://shibboleth.atlassian.net/browse/IDP-1757?atlOrigin=eyJpIjoiYzgyYTZmMzJmYjU1NGVkMjljZTUzNzcxNWE1YzMwMWIiLCJwIjoiaiJ9 )

Rod Widdowson ( https://shibboleth.atlassian.net/secure/ViewProfile.jspa?accountId=59fb32bbc24efb3c4ed3c977 ) , Thanks for the nudge! Got to some quick review on it.

From a usability perspective, feels about right in the existing toolset.

I like the property file approach and actually pointed it at the $idp-home/conf/idp.properties file for the extra fields.

Suggestions/observations:

* Suggestion 1 :

* While properties for this can be standalone, that a practice of using the idp.properties file be the place to put the idp.metadata.* stuff.

* Rationale: all the things in one place, and all the things to be injected for the installer 🙂

* Observation:

* I left off the logo from the property file and it had the default dummy logo, and was somewhat surprised (ie hey, i didn’t put that there, I thought it would remain silent on it 🙂 )

* I see the docs say the defaults would be used.
* Suggestion 2 : maybe put in the defaults in the docs at least?
* Observation 2: My initial impression on this was that there’s a template for it and maybe tinker with the template to see how it works and if there was cleverness on if/then/else on things. Doesn’t look like there is (which is fine). Sounds like all the logic is wrapped up into the CLI – right?

* Rationale: I’m asking as I was also trying to invoke $idp_url/idp/Metadatagen as a way to see the live metadata or trigger it’s recalculation – likely a wrong idea?

* if there’s an admin url for it, then the docs would benefit from having it in there and how to invoke rather than guessing. If it can’t then say it is only a CLI to curtail goose-chasing
* Rationale 2: if we can invoke a url it means improved mgmt of a containered IdP that in turn responds with proper and current-to-its-config metadata.
* Why recalculate? Well, some sites want a url to fetch from and having the metadatagen.sh generate good metadata is good and better would be to have it somehow published.
* suggestion 3 :

* if the IdP fetches idp-metadata.xml and just echo’s it out, then maybe an enhancement to the documentation for metadatagen (or the idp itself in mainstream config story) is to recommend it in the usage to update idp-metadata.xml?
* Rationale: Sites often ask ‘do I need to update this file on disk? We say, yes, to stay current however the federation metadata may be slightly different (e.g. entity categories, sirtfi, other things like registration instant). HOWEVER, other services would benefit from fetching the known good url for the idp’s metadata that metadatagen.sh would output to (ie the idp-metadata.xml).

Thanks again for the work and hope this feedback helps!

( https://shibboleth.atlassian.net/browse/IDP-1757#add-comment?atlOrigin=eyJpIjoiYzgyYTZmMzJmYjU1NGVkMjljZTUzNzcxNWE1YzMwMWIiLCJwIjoiaiJ9 ) Add Comment ( https://shibboleth.atlassian.net/browse/IDP-1757#add-comment?atlOrigin=eyJpIjoiYzgyYTZmMzJmYjU1NGVkMjljZTUzNzcxNWE1YzMwMWIiLCJwIjoiaiJ9 )

Get Jira notifications on your phone! Download the Jira Cloud app for Android ( https://play.google.com/store/apps/details?id=com.atlassian.android.jira.core&referrer=utm_source%3DNotificationLink%26utm_medium%3DEmail ) or iOS ( https://itunes.apple.com/app/apple-store/id1006972087?pt=696495&ct=EmailNotificationLink&mt=8 ) This message was sent by Atlassian Jira (v1001.0.0-SNAPSHOT#100174- sha1:a164603 )
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/commits/attachments/20210823/49f851c5/attachment-0001.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: jira-generated-image-static-comment-icon-a84ed5a4-8257-4362-9200-cecc3e333218
Type: image/png
Size: 1084 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/commits/attachments/20210823/49f851c5/attachment-0003.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: jira-generated-image-avatar-2b9ea125-d931-460c-9f12-66be84920325
Type: image/png
Size: 457 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/commits/attachments/20210823/49f851c5/attachment-0004.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: jira-generated-image-static-footer-desktop-logo-5e84a4ea-83b0-4ee5-92e0-0f8f17496d31
Type: image/png
Size: 10805 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/commits/attachments/20210823/49f851c5/attachment-0005.png>


More information about the commits mailing list