Default Shibboleth SP configuration in packaged distributions
Cantor, Scott
cantor.2 at osu.edu
Tue Jan 26 10:03:27 EST 2016
On 1/26/16, 9:17 AM, "dev on behalf of Jorj Bauer" <dev-bounces at shibboleth.net on behalf of jorj at temple.edu> wrote:
>Who is responsible for the various vendor distributable packages of shibd?
The project distributes RPMs from the OBS yum repositories, and a tarball, and a Windows installer. Anything for an unsupported platform (e.g. Debian) is from volunteers.
>The default shibboleth2.xml configuration (in the current Debian8
>package, and at least in the installed version of CentOS packages that I
>see on some hosts, although I admit I haven't checked the latest version
>of those packages) has this commented-out stanza:
That's in the distribution (literally is in git, in other words).
>We've found a vendor that uncommented that in production and were using
>it - until 1/6/2016, when federation.org was apparently registered by
>some new owner, and that URL stopped hosting metadata. Their cached
>metadata expired some time early yesterday and hilarity ensued. [1]
That URL never hosted any metadata that the project has anything to do with. Somebody using that literally has no idea what they're doing and probably was being intentionally compromised. That's far from hilarious, obviously.
>It would make sense to me if that default URL were InCommon's metadata URL:
>
> http://md.incommon.org/InCommon/InCommon-metadata.xml
That would not be appropriate.
>... but maybe there's a good reason for it to point to something
>completely broken instead, like
>
> http://example.org/federation-metadata.xml
Agreed, strongly, and my apologies for not realizing I picked that name. Please file an issue, I'll fix it in the next patch.
-- Scott
More information about the dev
mailing list