Shibboleth FileBackedHTTPMetadataProvider

Tom Scavo trscavo at internet2.edu
Tue Mar 29 09:15:45 EDT 2016


[I'll use Shib IdP V3 syntax below but my question is intended to
cover both the IdP and SP]

Basically, I'm trying to understand the strategy around the backing
file. I assume the backing file is consulted if the HTTP request for
metadata fails. Is the startup strategy different than the normal
refresh strategy?

Suppose the MetadataProvider contains the following filter:

<MetadataFilter xsi:type="SignatureValidation">

If signature verification fails, is the backing file consulted or does
the process stop dead in its tracks?

Same question for the following filter:

<MetadataFilter xsi:type="metadata:RequiredValidUntil">

I'll capture in the wiki anything I learn here.

Thanks,

Tom


More information about the dev mailing list