include SignatureValidation filter with FileBackedHTTPMetadataProvider

Cantor, Scott cantor.2 at osu.edu
Tue Dec 19 17:31:34 EST 2017


On 12/19/17, 4:01 PM, "dev on behalf of Tom Scavo" <dev-bounces at shibboleth.net on behalf of trscavo at gmail.com> wrote:

> OTOH, if the metadata is not signed, what should the default action of
> the software be? I believe it should go out to the network by default.
> If the deployer makes an explicit decision to grab a locally trusted
> file instead, then that's fine. All I'm saying is that shouldn't be
> the default behavior of the software (which is it if the deployer
> happens to use FileBackedHTTPMetadataProvider).

We don't agree with that. At least I don't, I guess the rest of the team can speak for themselves, but Brent presumably wouldn't have implemented it that way if he felt it was incorrect to do so.

-- Scott




More information about the dev mailing list