IdPv3 and its metadata ?
Ian Young
ian at iay.org.uk
Wed Jan 8 15:21:53 EST 2014
On 8 Jan 2014, at 19:49, Tom Zeller <tzeller at dragonacea.biz> wrote:
> Will IdPv3 consume its own metadata ? (I assume not)
I'm fairly sure we have discussed this at least once, and came down hard against it doing so. I'd certainly prefer that it doesn't, as this introduces some really hard to debug behaviours when the metadata fed back from the federations you're a member of clash with the "real" values.
> Should the IdPv3 installer produce a metadata file suitable for
> consumption by relying parties ? (I assume yes)
That's one option, but I'd prefer that we think in terms of something equivalent to what the SP does, if at all possible. Producing a static file and publishing doesn't allow the automatically generated metadata to adapt when you make configuration changes or perform upgrades, which I think helps a lot with things like additional profiles and algorithm agility metadata.
> If yes above, should the IdPv3 metadata file be the same or similar to
> the idp-metadata.xml file the v2 installer creates, or should it look
> like example-metadata.xml in the SP distribution ?
>
> Should IdPv3 have a metadata handler listening at /profile/Metadata/SAML ?
I'm not sure what the endpoint should be (/SAML/Metadata seems more natural) but if the question is "should the automatically generated metadata for the entity be available by default at a pre-defined location" I'd say that the answer should be yes. This means that it's easier for a federation operator to help out a relatively unskilled IdP deployer, for example.
-- Ian
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 5943 bytes
Desc: not available
Url : http://shibboleth.net/pipermail/dev/attachments/20140108/9c39400f/attachment.bin
More information about the dev
mailing list