Default Shibboleth SP configuration in packaged distributions

Jorj Bauer jorj at temple.edu
Wed Jan 27 09:46:37 EST 2016


Created SSPCPP-675. Apologies if I've put it in the wrong project.

-- Jorj


On 01/26/2016 10:03 AM, Cantor, Scott wrote:
> On 1/26/16, 9:17 AM, "dev on behalf of Jorj Bauer" <dev-bounces at shibboleth.net on behalf of jorj at temple.edu> wrote:
>
>
>
>> Who is responsible for the various vendor distributable packages of shibd?
>
> The project distributes RPMs from the OBS yum repositories, and a tarball, and a Windows installer. Anything for an unsupported platform (e.g. Debian) is from volunteers.
>
>> The default shibboleth2.xml configuration (in the current Debian8
>> package, and at least in the installed version of CentOS packages that I
>> see on some hosts, although I admit I haven't checked the latest version
>> of those packages) has this commented-out stanza:
>
> That's in the distribution (literally is in git, in other words).
>
>> We've found a vendor that uncommented that in production and were using
>> it - until 1/6/2016, when federation.org was apparently registered by
>> some new owner, and that URL stopped hosting metadata. Their cached
>> metadata expired some time early yesterday and hilarity ensued. [1]
>
> That URL never hosted any metadata that the project has anything to do with. Somebody using that literally has no idea what they're doing and probably was being intentionally compromised. That's far from hilarious, obviously.
>
>> It would make sense to me if that default URL were InCommon's metadata URL:
>>
>>    http://md.incommon.org/InCommon/InCommon-metadata.xml
>
> That would not be appropriate.
>
>> ... but maybe there's a good reason for it to point to something
>> completely broken instead, like
>>
>>    http://example.org/federation-metadata.xml
>
> Agreed, strongly, and my apologies for not realizing I picked that name. Please file an issue, I'll fix it in the next patch.
>
> -- Scott
>


More information about the dev mailing list