Metadata generation revisited.
Nate Klingenstein
ndk at internet2.edu
Wed Oct 22 06:16:51 EDT 2014
1) MDUI. There currently is none. IDP-93 suggests adding it. I am happy
with the current plan which is to add something, but leave it commented out.
I just mention this for completeness.
Having been through one round of Shibboleth-branded error pages around the world, I'm happy with that plan too.
2) IDP-481 suggests a warning at the top. I'll just add whatever the SP has
suitable adjusted to say "No the IDP doesn't need it, not it's not up to
date". Again, mentioned only for completeness.
I think this is fine. You'll definitely want to highlight the static nature of the metadata, though, since that's different from what the SP does.
2) SAML2 AttributeQuery. There is a proposal in IDP-481 to not add this, or
to comment it out (since in 95% of cases it just causes everyone extra
work). Note that this is NOT the same discussion as "can we configure
backchannel off" (and even less about whether that is a default), this is
just about dropping one backchannel endpoint which just causes a lot of
customers to waste their time. Scott's comment is :
I don't think dropping one endpoint really helps because there's so much more than AttributeQueries that have the exact story.
I'd sooner see a flag that deployers can toggle between "I do support back channel" and "I don't support back channel" that would be reflected in metadata as well.
I know I'm asking for unicorns in November, but I like them.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/dev/attachments/20141022/3312646c/attachment.html
More information about the dev
mailing list