Possible problem with validUntil in opensaml

Chad La Joie lajoie at itumi.biz
Mon Jun 18 15:05:19 BST 2012


That is currently expected behavior.  There was a thread about it on,
I think, the user's list some time ago.

The short of it is the current IdP treats the metadata file as an
atomic whole so if one thing is invalid it scraps the whole file.
That's the most conservative approach to take.  v3 does not take the
view that the file is an atomic item and so it should be easier to
just discard the expired EntitiesDescriptors, EntityDescriptors, and
Roles.

On Mon, Jun 18, 2012 at 9:56 AM, Leif Johansson <leifj at sunet.se> wrote:
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>
> I just ran into a strange issue: I have (or rather had) metadata where
> one of the EntityDescriptor elements had a validUntil tag which had
> expired. The containing EntitiesDescriptor element had a validUntil
> attribute which was still current. Both validUntil attributes were
> syntactically correct timestamps.
>
> An admittedly strange situation, but...
>
> The effect on consuming this metadata in 2.4.5 IdPs was very strange:
> it seemed like the "inner" validUntil element caused the full metadata
> to be treated as expired.
>
>        Best Leif
> -----BEGIN PGP SIGNATURE-----
> Version: GnuPG v1.4.11 (GNU/Linux)
> Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/
>
> iEYEARECAAYFAk/fM5QACgkQ8Jx8FtbMZnfiggCfVt2OyUFRE5tyXnMDd1Yl6Rmb
> f+EAoKfnKaNixbKAiPGVQOHNhVbolzEq
> =wbrs
> -----END PGP SIGNATURE-----
> --
> To unsubscribe from this list send an email to dev-unsubscribe at shibboleth.net



-- 
Chad La Joie
www.itumi.biz
trusted identities, delivered


More information about the dev mailing list