Default Shibboleth SP configuration in packaged distributions

Cantor, Scott cantor.2 at osu.edu
Tue Jan 26 10:03:27 EST 2016


On 1/26/16, 9:17 AM, "dev on behalf of Jorj Bauer" <dev-bounces at shibboleth.net on behalf of jorj at temple.edu> wrote:



>Who is responsible for the various vendor distributable packages of shibd?

The project distributes RPMs from the OBS yum repositories, and a tarball, and a Windows installer. Anything for an unsupported platform (e.g. Debian) is from volunteers.

>The default shibboleth2.xml configuration (in the current Debian8 
>package, and at least in the installed version of CentOS packages that I 
>see on some hosts, although I admit I haven't checked the latest version 
>of those packages) has this commented-out stanza:

That's in the distribution (literally is in git, in other words).

>We've found a vendor that uncommented that in production and were using 
>it - until 1/6/2016, when federation.org was apparently registered by 
>some new owner, and that URL stopped hosting metadata. Their cached 
>metadata expired some time early yesterday and hilarity ensued. [1]

That URL never hosted any metadata that the project has anything to do with. Somebody using that literally has no idea what they're doing and probably was being intentionally compromised. That's far from hilarious, obviously.

>It would make sense to me if that default URL were InCommon's metadata URL:
>
>   http://md.incommon.org/InCommon/InCommon-metadata.xml

That would not be appropriate.

>... but maybe there's a good reason for it to point to something 
>completely broken instead, like
>
>   http://example.org/federation-metadata.xml

Agreed, strongly, and my apologies for not realizing I picked that name. Please file an issue, I'll fix it in the next patch.

-- Scott



More information about the dev mailing list