IdPv3 and its metadata ?
Chris Phillips
Chris.Phillips at canarie.ca
Thu Jan 9 07:40:43 EST 2014
If there was some straightforward way to 'decorate' the metadata that would allow things like MDUI elements, contact info etc, or whatever the default metadata must look like for a Feds entity record to be at the dynamic URL (eduGAIN profile comes to mind), that would be helpful.
Currently this is all externalized from the IDp and adds extra steps for on boarding/maintaining an IDp entry in a registry, if you have one..
C
/mobile_____________________
chris.phillips at canarie.ca
> On Jan 9, 2014, at 4:42 AM, "Rod Widdowson" <rdw at steadingsoftware.com> wrote:
>
> Coming in late here. I'd love to see proper dynamic metadata generation in
> V3, but from a project management point of view it just doesn't feel
> feasible to include in V3.0. I guess all that I would suggest is that we
> remember the desirability to provide this long term and do not architect
> against it...
>
>> If the published metadata is static (like v2) rather than dynamic
>> (like the SP), then is the publishing of that static metadata still
>> useful to the federation operator ?
>
> That’s one for Tom, Ian &co, but my instinct is that having statically
> generated metadata served up on an endpoint is a bad idea. It gives people
> the impression that the metadata is dynamic when it isn't and it encourages
> people to add dynamic metadata providers to their SP without considering the
> security implications. Additionally, if a sysadmin really wants the
> metadata served up, they can arrange it.
>
> The only argument I could see in favour of keeping this is backwards
> compatibility - I suppose there may be SPs out there that already use the
> static metadata provider in IdPV2, and they would need to be changed...
>
> FWIW
> /Rod
>
> --
> To unsubscribe from this list send an email to dev-unsubscribe at shibboleth.net
More information about the dev
mailing list