expirationWarningThreshold
Cantor, Scott
cantor.2 at osu.edu
Mon May 22 10:04:10 EDT 2017
> If we were starting from scratch, would it make sense to expose the
> latter two configurations only? AFAICT, the first one isn't really an
> option. I claim an implementation doesn't have the option of ignoring
> the validUntil attribute. Do you agree?
No, the low level resolver code is available for general metadata processing that may have a reason to be seeing all metadata, expired or not.
Whether we document or mention the setting in the Shibboleth context is a different question, but as an option it's necessary.
As I keep saying, nobody who doesn't understand expirationWarningThreshold has any reason to use it. I'm inclined to say we should reverse the default change and put it back at 0 or something really small so that it doesn't impact anybody who doesn't choose to set it.
-- Scott
More information about the dev
mailing list