Metadata generation revisited.
Rod Widdowson
rdw at steadingsoftware.com
Wed Oct 22 04:17:19 EDT 2014
Bringing this to the list from JIRA so it gets a wider airing.
As per V2, the V3 initial install will generate something which is close to
appropriate metadata for the freshly installed IdP. In slight contrast to
V2 this is driven from idp.properties (plus the DNS name and a path to the
backchannel cert) which allows slightly cleaner handling of credentials.
I'll say that I am not sure that this is the correct solution
architecturally so I am loth to spend too much time developing this further
until we agree that this is the way to go.
Anyway there are currently a few issues I'd like to air slightly more
widely.
1) MDUI. There currently is none. IDP-93 suggests adding it. I am happy
with the current plan which is to add something, but leave it commented out.
I just mention this for completeness.
2) IDP-481 suggests a warning at the top. I'll just add whatever the SP has
suitable adjusted to say "No the IDP doesn't need it, not it's not up to
date". Again, mentioned only for completeness.
2) SAML2 AttributeQuery. There is a proposal in IDP-481 to not add this, or
to comment it out (since in 95% of cases it just causes everyone extra
work). Note that this is NOT the same discussion as "can we configure
backchannel off" (and even less about whether that is a default), this is
just about dropping one backchannel endpoint which just causes a lot of
customers to waste their time. Scott's comment is :
> Also wondering if we want to omit the SAML 2 attribute query endpoint by
default. We could comment
> that out, but that will just show up in lots of metadata if we do that.
Maybe a comment placeholder that
> says it's being omitted. Need to discuss I guess.
So, can we discuss?
Rod
More information about the dev
mailing list