<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0, maximum-scale=1.0">
<base href="https://issues.shibboleth.net/jira">
<title>Message Title</title>
</head>
<body class="jira" style="color: #333333; font-family: Arial, sans-serif; font-size: 14px; line-height: 1.429">
<table id="background-table" cellpadding="0" cellspacing="0" width="100%" style="border-collapse: collapse; mso-table-lspace: 0pt; mso-table-rspace: 0pt; background-color: #f5f5f5; border-collapse: collapse; mso-table-lspace: 0pt; mso-table-rspace: 0pt" bgcolor="#f5f5f5">
<!-- header here -->
<tbody>
<tr>
<td id="header-pattern-container" style="padding: 0px; border-collapse: collapse; padding: 10px 20px">
<table id="header-pattern" cellspacing="0" cellpadding="0" border="0" style="border-collapse: collapse; mso-table-lspace: 0pt; mso-table-rspace: 0pt">
<tbody>
<tr>
<td id="header-avatar-image-container" valign="top" style="padding: 0px; border-collapse: collapse; vertical-align: top; width: 32px; padding-right: 8px" width="32"> <img id="header-avatar-image" class="image_fix" src="cid:jira-generated-image-avatar-5a0417bf-dc2d-4e8f-b4aa-5c579568ee72" height="32" width="32" border="0" style="border-radius: 3px; vertical-align: top"> </td>
<td id="header-text-container" valign="middle" style="padding: 0px; border-collapse: collapse; vertical-align: middle; font-family: Arial, sans-serif; font-size: 14px; line-height: 20px; mso-line-height-rule: exactly; mso-text-raise: 1px"> <a class="user-hover" rel="trscavo@ncsa.illinois.edu" id="email_trscavo@ncsa.illinois.edu" href="https://issues.shibboleth.net/jira/secure/ViewProfile.jspa?name=trscavo%40ncsa.illinois.edu" style="color:#3b73af;; color: #3b73af; text-decoration: none">Thomas Scavo</a> <strong>created</strong> an issue </td>
</tr>
</tbody>
</table> </td>
</tr>
<tr>
<td id="email-content-container" style="padding: 0px; border-collapse: collapse; padding: 0 20px">
<table id="email-content-table" cellspacing="0" cellpadding="0" border="0" width="100%" style="border-collapse: collapse; mso-table-lspace: 0pt; mso-table-rspace: 0pt; border-spacing: 0; border-collapse: separate">
<tbody>
<tr>
<!-- there needs to be content in the cell for it to render in some clients -->
<td class="email-content-rounded-top mobile-expand" style="padding: 0px; border-collapse: collapse; color: #ffffff; padding: 0 15px 0 16px; height: 15px; background-color: #ffffff; border-left: 1px solid #cccccc; border-top: 1px solid #cccccc; border-right: 1px solid #cccccc; border-bottom: 0; border-top-right-radius: 5px; border-top-left-radius: 5px; height: 10px; line-height: 10px; padding: 0 15px 0 16px; mso-line-height-rule: exactly" height="10" bgcolor="#ffffff"> </td>
</tr>
<tr>
<td class="email-content-main mobile-expand " style="padding: 0px; border-collapse: collapse; border-left: 1px solid #cccccc; border-right: 1px solid #cccccc; border-top: 0; border-bottom: 0; padding: 0 15px 0 16px; background-color: #ffffff" bgcolor="#ffffff">
<table class="page-title-pattern" cellspacing="0" cellpadding="0" border="0" width="100%" style="border-collapse: collapse; mso-table-lspace: 0pt; mso-table-rspace: 0pt">
<tbody>
<tr>
<td class="page-title-pattern-first-line " style="padding: 0px; border-collapse: collapse; font-family: Arial, sans-serif; font-size: 14px; padding-top: 10px"> <a href="https://issues.shibboleth.net/jira/browse/IDP" style="color: #3b73af; text-decoration: none">Identity Provider</a> / <a href="https://issues.shibboleth.net/jira/browse/IDP-1245" style="color: #3b73af; text-decoration: none"><img src="cid:jira-generated-image-static-story-a92275a7-a7cf-4665-bd1d-b32197b1a56d" height="16" width="16" border="0" align="absmiddle" alt="Story" style="vertical-align: text-bottom"></a> <a href="https://issues.shibboleth.net/jira/browse/IDP-1245" style="color: #3b73af; text-decoration: none">IDP-1245</a> </td>
</tr>
<tr>
<td style="vertical-align: top;; padding: 0px; border-collapse: collapse; padding-right: 5px; font-size: 20px; line-height: 30px; mso-line-height-rule: exactly" class="page-title-pattern-header-container"> <span class="page-title-pattern-header" style="font-family: Arial, sans-serif; padding: 0; font-size: 20px; line-height: 30px; mso-text-raise: 2px; mso-line-height-rule: exactly; vertical-align: middle"> <a href="https://issues.shibboleth.net/jira/browse/IDP-1245" style="color: #3b73af; text-decoration: none">Metadata Early Warning System for Shibboleth</a> </span> </td>
</tr>
</tbody>
</table> </td>
</tr>
<tr>
<td class="email-content-main mobile-expand wrapper-special-margin" style="padding: 0px; border-collapse: collapse; border-left: 1px solid #cccccc; border-right: 1px solid #cccccc; border-top: 0; border-bottom: 0; padding: 0 15px 0 16px; background-color: #ffffff; padding-top: 10px; padding-bottom: 5px" bgcolor="#ffffff">
<table class="keyvalue-table" style="border-collapse: collapse; mso-table-lspace: 0pt; mso-table-rspace: 0pt">
<tbody>
<tr>
<th style="color: #707070; font: normal 14px/20px Arial, sans-serif; text-align: left; vertical-align: top; padding: 2px 0">Issue Type:</th>
<td class="has-icon" style="padding: 0px; border-collapse: collapse; font: normal 14px/20px Arial, sans-serif; padding: 2px 0 2px 5px; vertical-align: top"> <img src="cid:jira-generated-image-static-story-a92275a7-a7cf-4665-bd1d-b32197b1a56d" height="16" width="16" border="0" align="absmiddle" alt="Story" style="vertical-align: text-bottom"> Story </td>
</tr>
<tr>
<th style="color: #707070; font: normal 14px/20px Arial, sans-serif; text-align: left; vertical-align: top; padding: 2px 0">Assignee:</th>
<td style="padding: 0px; border-collapse: collapse; font: normal 14px/20px Arial, sans-serif; padding: 2px 0 2px 5px; vertical-align: top"> <a class="user-hover" rel="tzeller@shibboleth.net" id="email_tzeller@shibboleth.net" href="https://issues.shibboleth.net/jira/secure/ViewProfile.jspa?name=tzeller%40shibboleth.net" style="color:#3b73af;; color: #3b73af; text-decoration: none">Tom Zeller</a> </td>
</tr>
<tr>
<th style="color: #707070; font: normal 14px/20px Arial, sans-serif; text-align: left; vertical-align: top; padding: 2px 0">Created:</th>
<td style="padding: 0px; border-collapse: collapse; font: normal 14px/20px Arial, sans-serif; padding: 2px 0 2px 5px; vertical-align: top"> 08/Jan/18 12:51 PM </td>
</tr>
<tr>
<th style="color: #707070; font: normal 14px/20px Arial, sans-serif; text-align: left; vertical-align: top; padding: 2px 0">Environment:</th>
<td style="padding: 0px; border-collapse: collapse; font: normal 14px/20px Arial, sans-serif; padding: 2px 0 2px 5px; vertical-align: top"> </td>
</tr>
<tr>
<th style="color: #707070; font: normal 14px/20px Arial, sans-serif; text-align: left; vertical-align: top; padding: 2px 0">Priority:</th>
<td class="has-icon" style="padding: 0px; border-collapse: collapse; font: normal 14px/20px Arial, sans-serif; padding: 2px 0 2px 5px; vertical-align: top"> <img src="cid:jira-generated-image-static-major-9ac83004-2e1b-435d-b491-413193254582" height="16" width="16" border="0" align="absmiddle" alt="Major" style="vertical-align: text-bottom"> Major </td>
</tr>
<tr>
<th style="color: #707070; font: normal 14px/20px Arial, sans-serif; text-align: left; vertical-align: top; padding: 2px 0">Reporter:</th>
<td style="padding: 0px; border-collapse: collapse; font: normal 14px/20px Arial, sans-serif; padding: 2px 0 2px 5px; vertical-align: top"> <a class="user-hover" rel="trscavo@ncsa.illinois.edu" id="email_trscavo@ncsa.illinois.edu" href="https://issues.shibboleth.net/jira/secure/ViewProfile.jspa?name=trscavo%40ncsa.illinois.edu" style="color:#3b73af;; color: #3b73af; text-decoration: none">Thomas Scavo</a> </td>
</tr>
</tbody>
</table> </td>
</tr>
<tr>
<td class="email-content-main mobile-expand issue-description-container" style="padding: 0px; border-collapse: collapse; border-left: 1px solid #cccccc; border-right: 1px solid #cccccc; border-top: 0; border-bottom: 0; padding: 0 15px 0 16px; background-color: #ffffff; padding-top: 5px; padding-bottom: 10px" bgcolor="#ffffff">
<table class="text-paragraph-pattern" cellspacing="0" cellpadding="0" border="0" width="100%" style="border-collapse: collapse; mso-table-lspace: 0pt; mso-table-rspace: 0pt; font-family: Arial, sans-serif; font-size: 14px; line-height: 20px; mso-line-height-rule: exactly; mso-text-raise: 2px">
<tbody>
<tr>
<td class="text-paragraph-pattern-container mobile-resize-text " style="padding: 0px; border-collapse: collapse; padding: 0 0 10px 0"> <p style="margin-top:0;margin-bottom:10px;; margin: 10px 0 0 0; margin-top: 0">This is a story about a metadata early warning system for the Shibboleth IdP.</p> <p style="margin-top:0;margin-bottom:10px;; margin: 10px 0 0 0">As you probably know, eduGAIN now requires the <tt>@creationInstant</tt> attribute on all imported metadata. Here are some suggestions how the Shibboleth IdP might leverage this new bit of information.</p> <p style="margin-top:0;margin-bottom:10px;; margin: 10px 0 0 0">There are at least three time intervals of interest to deployers that rely on federation metadata:</p>
<ol>
<li><em>The Expiration Warning Interval</em> is determined by its right-hand endpoint (<tt>@validUntil</tt>) and its length (<tt>expirationWarningInterval</tt>).</li>
<li>The <em>Freshness Interval</em> is determined by its left-hand endpoint (<tt>@creationInstant</tt>) and its length (<tt>freshnessInterval</tt>).</li>
<li>The <em>Validity Interval</em> is determined by its endpoints, <tt>@creationInstant</tt> and <tt>@validUntil</tt>, respectively.</li>
</ol> <p style="margin-top:0;margin-bottom:10px;; margin: 10px 0 0 0">The lengths of the first two intervals are configurable. For the most part, reasonable values for the lengths of the Expiration Warning Interval and the Freshness Interval depend on the actual Validity Interval of the metadata in question. In practice, the latter varies between 4 days and three weeks across federations.</p> <h2 style="margin: 10px 0 0 0; font-size: 20px; font-weight: normal; line-height: 1.500; margin: 40px 0 0 0"><a name="ExpirationWarningInterval" style="color: #3b73af; text-decoration: none"></a>Expiration Warning Interval</h2> <p style="margin-top:0;margin-bottom:10px;; margin: 10px 0 0 0">The Expiration Warning Interval is determined by the value of the <tt>@validUntil</tt> attribute and an interval length. If the current time is captured by the Expiration Warning Interval, a warning message is logged.</p> <p style="margin-top:0;margin-bottom:10px;; margin: 10px 0 0 0">(The Shibboleth IdP has a setting called <tt>expirationWarningThreshold</tt> whose value is an ISO 8601 Duration. Unfortunately, the setting name is a misnomer. A better name would be <tt>expirationWarningIntervalLength</tt> or perhaps just <tt>expirationWarningInterval</tt>. The latter is consistent with existing parameters called <tt>cleanupTaskInterval</tt> and <tt>maxValidityInterval</tt>. Note: Parameter <tt>expirationWarningThreshold</tt> has been replaced by <tt>expirationWarningInterval</tt> in what follows.)</p> <p style="margin-top:0;margin-bottom:10px;; margin: 10px 0 0 0">More importantly, support for the Expiration Warning Interval by itself is not enough. As a deployer, I want to be aware of anomalies in the metadata as early as possible in the metadata lifecycle. The <tt>@creationInstant</tt> attribute may be used for this purpose.</p> <h2 style="margin: 10px 0 0 0; font-size: 20px; font-weight: normal; line-height: 1.500; margin: 40px 0 0 0"><a name="%C2%A0FreshnessInterval" style="color: #3b73af; text-decoration: none"></a> Freshness Interval</h2> <p style="margin-top:0;margin-bottom:10px;; margin: 10px 0 0 0">The Freshness Interval is determined by the value of the <tt>@creationInstant</tt> attribute and an interval length. The Freshness Interval is a GREEN subinterval whereas the Expiration Warning Interval is a RED subinterval. Between these two subintervals is a no-name YELLOW subinterval that indicates stale metadata.</p> <h2 style="margin: 10px 0 0 0; font-size: 20px; font-weight: normal; line-height: 1.500; margin: 40px 0 0 0"><a name="ValidityInterval" style="color: #3b73af; text-decoration: none"></a>Validity Interval</h2> <p style="margin-top:0;margin-bottom:10px;; margin: 10px 0 0 0">The Expiration Warning Interval and the Freshness Interval partition the Validity Interval into GREEN, YELLOW, and RED subintervals, respectively. The actual Validity Interval must be stable since reasonable values for the other interval lengths depend on it.</p> <h2 style="margin: 10px 0 0 0; font-size: 20px; font-weight: normal; line-height: 1.500; margin: 40px 0 0 0"><a name="Specification" style="color: #3b73af; text-decoration: none"></a>Specification</h2>
<ol>
<li>Every <tt>MetadataProvider</tt> has an independently configurable early warning system, which is enabled by default</li>
<li>By default, <tt>requireValidMetadata=true</tt></li>
<li>Reject the metadata if all of the following are true:
<ol>
<li>The <tt>requireValidMetadata</tt> config parameter is set to true (which it is by default)</li>
<li>The <tt>@validUntil</tt> attribute exists in the metadata</li>
<li>The value of <tt>@validUntil</tt> is in the past</li>
</ol> </li>
<li>If <tt>requireValidMetadata=false</tt>, the early warning system is automatically disabled (in which case any of the configurable parameters listed below are ignored)</li>
<li>Define three locally configurable parameters:
<ol>
<li><tt>expirationWarningInterval</tt>, the length of the Expiration Warning Interval (default: <tt>P2D</tt>)</li>
<li><tt>freshnessInterval</tt>, the length of the Freshness Interval (no default)</li>
<li><tt>expectedValidityInterval</tt>, the expected length of the Validity Interval (no default)</li>
</ol> </li>
<li>For each attempted metadata refresh (whether or not fresh metadata is obtained), log a expiration warning message if all of the following are true:
<ol>
<li>The <tt>requireValidMetadata</tt> config parameter is set to true (which it is by default)</li>
<li>The <tt>@validUntil</tt> attribute exists in the metadata</li>
<li>The current time exceeds the left-hand endpoint of the Expiration Warning Interval</li>
</ol> </li>
<li>For each attempted metadata refresh (whether or not fresh metadata is obtained), log a stale warning message if all of the following are true:
<ol>
<li>The <tt>requireValidMetadata</tt> config parameter is set to true (which it is by default)</li>
<li>An expiration warning message has <b>not</b> been logged</li>
<li>The length of the Freshness Interval (<tt>freshnessInterval</tt>) is explicitly configured</li>
<li>The <tt>@creationInstant</tt> attribute exists in the metadata</li>
<li>The current time exceeds the right-hand endpoint of the Freshness Interval</li>
</ol> </li>
<li>For each attempted metadata refresh (whether or not fresh metadata is obtained), log a warning message if all of the following are true:
<ol>
<li>The <tt>requireValidMetadata</tt> config parameter is set to true (which it is by default)</li>
<li>The expected length of the Validity Interval (<tt>expectedValidityInterval</tt>) is explicitly configured</li>
<li>Both <tt>@creationInstant</tt> and <tt>@validUntil</tt> exist in the metadata</li>
<li>The actual length of the Validity Interval (in metadata) is different than the expected length of the interval</li>
</ol> </li>
</ol> <p style="margin-top:0;margin-bottom:10px;; margin: 10px 0 0 0">To accompany the early warning system, a new metadata filter called <tt>RequiredCreationInstant</tt> is needed. The <tt>RequiredCreationInstant</tt> filter is similar to the <tt>RequiredValidUntil</tt> filter but with no configurable attributes. (Under the covers, the <tt>RequiredCreationInstant</tt> filter ensures that the value of the <tt>@creationInstant</tt> attribute is not in the future.)</p> <h2 style="margin: 10px 0 0 0; font-size: 20px; font-weight: normal; line-height: 1.500; margin: 40px 0 0 0"><a name="Documentation" style="color: #3b73af; text-decoration: none"></a>Documentation</h2> <h3 style="margin: 10px 0 0 0; font-size: 16px; line-height: 1.563; margin: 30px 0 0 0; margin-top: 10px"><a name="Attributes" style="color: #3b73af; text-decoration: none"></a>Attributes</h3> <p style="margin-top:0;margin-bottom:10px;; margin: 10px 0 0 0"><em>Name:</em> <tt>expirationWarningInterval</tt><br> <em>Type:</em> ISO 8601 Duration<br> <em>Default:</em> P2D<br> <em>Short Description:</em> The right-hand endpoint of the Expiration Warning Interval is the value of the <tt>@validUntil</tt> attribute in metadata. The length of the interval is given by the value of the <tt>expirationWarningInterval</tt> config parameter. A warning message is logged if the current time exceeds the left-hand endpoint of the interval.<br> <em>Long Description:</em><br> The Expiration Warning Interval is determined by its right-hand endpoint (<tt>@validUntil</tt>) and its length (<tt>expirationWarningInterval</tt>). The latter is configurable.</p> <p style="margin-top:0;margin-bottom:10px;; margin: 10px 0 0 0">For each attempted metadata refresh (whether or not fresh metadata is obtained), an expiration warning message is logged if all of the following are true:</p>
<ol>
<li>The <tt>requireValidMetadata</tt> config parameter is set to true (which it is by default)</li>
<li>The <tt>@validUntil</tt> attribute exists in the metadata</li>
<li>The current time exceeds the left-hand endpoint of the Expiration Warning Interval</li>
</ol> <p style="margin-top:0;margin-bottom:10px;; margin: 10px 0 0 0">The default value of <tt>expirationWarningInterval</tt> is <tt>P2D</tt>. To disable the warning feature, set the length to zero (<tt>PT0S</tt>).</p> <p style="margin-top:0;margin-bottom:10px;; margin: 10px 0 0 0">If the <tt>@validUntil</tt> attribute does not exist in the metadata, the Expiration Warning Interval can not be determined and no warning message is logged. To ensure that the metadata carries a <tt>@validUntil</tt> attribute, configure an instance of the <tt>RequiredValidUntil</tt> metadata filter into the pipeline process.</p> <p style="margin-top:0;margin-bottom:10px;; margin: 10px 0 0 0"><em>Name:</em> <tt>freshnessInterval</tt><br> <em>Type:</em> ISO 8601 Duration<br> <em>Default:</em> none<br> <em>Short Description:</em> The left-hand endpoint of the Freshness Interval is the value of the <tt>@creationInstant</tt> attribute in metadata. The length of the interval is given by the value of the <tt>freshnessInterval</tt> config parameter. A warning message is logged if the current time exceeds the right-hand endpoint of the Freshness Interval.<br> <em>Long Description:</em><br> The Freshness Interval is determined by its left-hand endpoint (<tt>@creationInstant</tt>) and its length (<tt>freshnessInterval</tt>). The latter is configurable.</p> <p style="margin-top:0;margin-bottom:10px;; margin: 10px 0 0 0">For each attempted metadata refresh (whether or not fresh metadata is obtained), a stale warning message is logged if all of the following are true:</p>
<ol>
<li>The <tt>requireValidMetadata</tt> config parameter is set to true (which it is by default)</li>
<li>An expiration warning message has <b>not</b> been logged</li>
<li>The length of the Freshness Interval (<tt>freshnessInterval</tt>) is explicitly configured</li>
<li>The <tt>@creationInstant</tt> attribute exists in the metadata</li>
<li>The current time exceeds the right-hand endpoint of the Freshness Interval</li>
</ol> <p style="margin-top:0;margin-bottom:10px;; margin: 10px 0 0 0">Config parameter <tt>freshnessInterval</tt> has no default value. If no value is configured, no warning is issued.</p> <p style="margin-top:0;margin-bottom:10px;; margin: 10px 0 0 0">If the <tt>@creationInstant</tt> attribute does not exist in the metadata, the Freshness Interval can not be determined and no warning message is logged. To ensure that the metadata carries a <tt>@creationInstant</tt> attribute, configure an instance of the <tt>RequiredCreationInstant</tt> metadata filter into the pipeline process.</p> <p style="margin-top:0;margin-bottom:10px;; margin: 10px 0 0 0"><em>Name:</em> <tt>expectedValidityInterval</tt><br> <em>Type:</em> ISO 8601 Duration<br> <em>Default:</em> none<br> <em>Short Description:</em> The endpoints of the Validity Interval are the values of the <tt>@creationInstant</tt> and <tt>@validUntil</tt> attributes (resp.) in metadata. The expected length of the interval is given by the value of the <tt>expectedValidityInterval</tt> parameter. A warning message is logged if the actual length of the Validity Interval (in metadata) is different than the expected length.<br> <em>Long Description:</em><br> The Validity Interval is determined by its endpoints, <tt>@creationInstant</tt> and <tt>@validUntil</tt>, respectively. The expected length of the Validity Interval (<tt>expectedValidityInterval</tt>) is configurable.</p> <p style="margin-top:0;margin-bottom:10px;; margin: 10px 0 0 0">For each attempted metadata refresh (whether or not fresh metadata is obtained), a warning message is logged if all of the following are true:</p>
<ol>
<li>The <tt>requireValidMetadata</tt> config parameter is set to true (which it is by default)</li>
<li>The expected length of the Validity Interval (<tt>expectedValidityInterval</tt>) is explicitly configured</li>
<li>Both <tt>@creationInstant</tt> and <tt>@validUntil</tt> exist in the metadata</li>
<li>The actual length of the Validity Interval (in metadata) is different than the expected length of the interval</li>
</ol> <p style="margin-top:0;margin-bottom:10px;; margin: 10px 0 0 0">Config parameter <tt>expectedValidityInterval</tt> has no default value. If no value is configured, no warning is issued.</p> <p style="margin-top:0;margin-bottom:10px;; margin: 10px 0 0 0">If either the <tt>@creationInstant</tt> attribute or the <tt>@validUntil</tt> attribute does not exist in the metadata, the Validity Interval can not be determined and no warning message is logged. To ensure that the metadata carries these attributes, configure instances of the <tt>RequiredCreationInstant</tt> metadata filter and the <tt>RequiredValidUntil</tt> metadata filter into the pipeline process.</p> <h3 style="margin: 10px 0 0 0; font-size: 16px; line-height: 1.563; margin: 30px 0 0 0"><a name="MetadataFilter" style="color: #3b73af; text-decoration: none"></a>Metadata Filter</h3> <p style="margin-top:0;margin-bottom:10px;; margin: 10px 0 0 0"><em>Name:</em> <tt>RequiredCreationInstant</tt><br> <em>Long Description:</em><br> The <tt>RequiredCreationInstant</tt> filter ensures that the metadata carries a <tt>@creationInstant</tt> XML attribute. This attribute is used to detect anomalies in published metadata. See the <tt>freshnessInterval</tt> and <tt>expectedValidityInterval</tt> config parameters for more information.</p> <p style="margin-top:0;margin-bottom:10px;; margin: 10px 0 0 0">The filter also ensures that the value of the <tt>@creationInstant</tt> attribute is not in the future. If it is, the metadata is dropped from the pipeline process.</p> <h2 style="margin: 10px 0 0 0; font-size: 20px; font-weight: normal; line-height: 1.500; margin: 40px 0 0 0"><a name="Examples" style="color: #3b73af; text-decoration: none"></a>Examples</h2>
<div class="code panel" style="border-width: 1px;; border: 1px solid #cccccc; background: #f5f5f5; font-size: 12px; line-height: 1.333; font-family: monospace; border: 1px solid #cccccc; -moz-border-radius: 3px 3px 3px 3px; border-radius: 3px 3px 3px 3px; margin: 9px 0">
<div class="codeContent panelContent" style="padding: 9px 12px">
<pre class="code-java" style="margin: 10px 0 0 0; margin-top: 0; max-height: 30em; overflow: auto; white-space: pre-wrap; word-wrap: normal">
<!--
A metadata source with a two-week Validity Interval and an
irregular publishing schedule (as indicated by the six-day
Freshness Interval). A publisher with an automated metadata
production process would have a more predictable publishing
schedule, in which <span class="code-keyword" style="color: #000091">case</span> the Freshness Interval could be
tightened.
Note that an instance of the RequiredCreationInstant filter
has been added to the filter pipeline. This ensures that a
@creationInstant attribute is included in the metadata and
that its value is not in the <span class="code-keyword" style="color: #000091">future</span>.
-->
<MetadataProvider id=<span class="code-quote" style="color: #009100">"myMD"</span> xsi:type=<span class="code-quote" style="color: #009100">"FileBackedHTTPMetadataProvider"</span>
xmlns=<span class="code-quote" style="color: #009100">"urn:mace:shibboleth:2.0:metadata"</span>
metadataURL=<span class="code-quote" style="color: #009100">"http:<span class="code-comment" style="color: #808080">//md.example.org/fed-metadata.xml"</span>
</span> backingFile=<span class="code-quote" style="color: #009100">"%{idp.home}/metadata/fed-metadata.xml"</span>
expirationWarningInterval=<span class="code-quote" style="color: #009100">"P3D"</span>
freshnessInterval=<span class="code-quote" style="color: #009100">"P6D"</span>
expectedValidityInterval=<span class="code-quote" style="color: #009100">"P14D"</span>>
<!--
Verify the signature on the EntitiesDescriptor element using a
trusted <span class="code-keyword" style="color: #000091">public</span> key certificate.
-->
<MetadataFilter xsi:type=<span class="code-quote" style="color: #009100">"SignatureValidation"</span> requireSignedRoot=<span class="code-quote" style="color: #009100">"<span class="code-keyword" style="color: #000091; color: #009100">true</span>"</span>
certificateFile=<span class="code-quote" style="color: #009100">"%{idp.home}/credentials/md-cert.pem"</span> />
<!--
Require a @validUntil attribute on the EntitiesDescriptor element
and make sure its value is no more than 14 days into the <span class="code-keyword" style="color: #000091">future</span>.
-->
<MetadataFilter xsi:type=<span class="code-quote" style="color: #009100">"RequiredValidUntil"</span> maxValidityInterval=<span class="code-quote" style="color: #009100">"P14D"</span>/>
<!--
Require a @creationInstant attribute on the EntitiesDescriptor element.
-->
<MetadataFilter xsi:type=<span class="code-quote" style="color: #009100">"RequiredCreationInstant"</span>/>
<!-- Consume all SP metadata in the aggregate -->
<MetadataFilter xsi:type=<span class="code-quote" style="color: #009100">"EntityRoleWhiteList"</span>>
<RetainedRole>md:SPSSODescriptor</RetainedRole>
</MetadataFilter>
</MetadataProvider>
</pre>
</div>
</div> </td>
</tr>
</tbody>
</table> </td>
</tr>
<tr>
<td class="email-content-main mobile-expand " style="padding: 0px; border-collapse: collapse; border-left: 1px solid #cccccc; border-right: 1px solid #cccccc; border-top: 0; border-bottom: 0; padding: 0 15px 0 16px; background-color: #ffffff" bgcolor="#ffffff">
<table id="actions-pattern" cellspacing="0" cellpadding="0" border="0" width="100%" style="border-collapse: collapse; mso-table-lspace: 0pt; mso-table-rspace: 0pt; font-family: Arial, sans-serif; font-size: 14px; line-height: 20px; mso-line-height-rule: exactly; mso-text-raise: 1px">
<tbody>
<tr>
<td id="actions-pattern-container" valign="middle" style="padding: 0px; border-collapse: collapse; padding: 10px 0 10px 24px; vertical-align: middle; padding-left: 0">
<table align="left" style="border-collapse: collapse; mso-table-lspace: 0pt; mso-table-rspace: 0pt">
<tbody>
<tr>
<td class="actions-pattern-action-icon-container" style="padding: 0px; border-collapse: collapse; font-family: Arial, sans-serif; font-size: 14px; line-height: 20px; mso-line-height-rule: exactly; mso-text-raise: 0; vertical-align: middle"> <a href="https://issues.shibboleth.net/jira/browse/IDP-1245#add-comment" target="_blank" title="Add Comment" style="color: #3b73af; text-decoration: none"> <img class="actions-pattern-action-icon-image" src="cid:jira-generated-image-static-comment-icon-ea83d34e-c808-472e-8e9c-519c722afb83" alt="Add Comment" title="Add Comment" height="16" width="16" border="0" style="vertical-align: middle"> </a> </td>
<td class="actions-pattern-action-text-container" style="padding: 0px; border-collapse: collapse; font-family: Arial, sans-serif; font-size: 14px; line-height: 20px; mso-line-height-rule: exactly; mso-text-raise: 4px; padding-left: 5px"> <a href="https://issues.shibboleth.net/jira/browse/IDP-1245#add-comment" target="_blank" title="Add Comment" style="color: #3b73af; text-decoration: none">Add Comment</a> </td>
</tr>
</tbody>
</table> </td>
</tr>
</tbody>
</table> </td>
</tr>
<!-- there needs to be content in the cell for it to render in some clients -->
<tr>
<td class="email-content-rounded-bottom mobile-expand" style="padding: 0px; border-collapse: collapse; color: #ffffff; padding: 0 15px 0 16px; height: 5px; line-height: 5px; background-color: #ffffff; border-top: 0; border-left: 1px solid #cccccc; border-bottom: 1px solid #cccccc; border-right: 1px solid #cccccc; border-bottom-right-radius: 5px; border-bottom-left-radius: 5px; mso-line-height-rule: exactly" height="5" bgcolor="#ffffff"> </td>
</tr>
</tbody>
</table> </td>
</tr>
<tr>
<td id="footer-pattern" style="padding: 0px; border-collapse: collapse; padding: 12px 20px">
<table id="footer-pattern-container" cellspacing="0" cellpadding="0" border="0" style="border-collapse: collapse; mso-table-lspace: 0pt; mso-table-rspace: 0pt">
<tbody>
<tr>
<td id="footer-pattern-text" class="mobile-resize-text" width="100%" style="padding: 0px; border-collapse: collapse; color: #999999; font-size: 12px; line-height: 18px; font-family: Arial, sans-serif; mso-line-height-rule: exactly; mso-text-raise: 2px"> This message was sent by Atlassian JIRA <span id="footer-build-information">(v7.4.2#74004-<span title="586975da6d5c632f4f0de24a42c40182e6b9ead0" data-commit-id="586975da6d5c632f4f0de24a42c40182e6b9ead0}">sha1:586975d</span>)</span> </td>
<td id="footer-pattern-logo-desktop-container" valign="top" style="padding: 0px; border-collapse: collapse; padding-left: 20px; vertical-align: top">
<table style="border-collapse: collapse; mso-table-lspace: 0pt; mso-table-rspace: 0pt">
<tbody>
<tr>
<td id="footer-pattern-logo-desktop-padding" style="padding: 0px; border-collapse: collapse; padding-top: 3px"> <img id="footer-pattern-logo-desktop" src="cid:jira-generated-image-static-footer-desktop-logo-ad2a9dce-4b83-4a36-9455-74c1968ee1b0" alt="Atlassian logo" title="Atlassian logo" width="169" height="36" class="image_fix"> </td>
</tr>
</tbody>
</table> </td>
</tr>
</tbody>
</table> </td>
</tr>
</tbody>
</table>
</body>
</html>