why is removeEmptyEntitiesDescriptors option needed?

Cantor, Scott cantor.2 at osu.edu
Fri Apr 10 13:08:04 EDT 2015


On 4/10/15, 8:42 AM, "Tom Scavo" <trscavo at gmail.com> wrote:

>The following new doc page for IdP V3:
>
>https://wiki.shibboleth.net/confluence/x/_gInAQ
>
>defines a removeEmptyEntitiesDescriptors XML attribute but AFAICT an
><md:EntitiesDescriptor> element MUST NOT be empty (according to the
>SAML2 Metadata Scema). Am I missing something?

I believe it's there so that if a filter runs and removes all its children, it won't be left behind empty (which is in fact not expected to be valid).

-- Scott



More information about the dev mailing list