expirationWarningThreshold

Tom Scavo trscavo at gmail.com
Wed May 24 09:24:00 EDT 2017


On Mon, May 22, 2017 at 1:40 PM, Brent Putman <putmanb at georgetown.edu> wrote:
>
> Aside from other low-level software use cases where
> you might really want to process "invalid" metadata, there's also the case
> of a broken metadata source that's taking awhile to get fixed.  If you're an
> IdP and you have to tell your users that they absolutely can't use some
> service because of some stale/expired metadata, due to hardcoded and
> un-changeable software behaviour, then that might be bad.  This flag puts
> that decision into the hands of the IdP deployer.  If they are OK with
> temporarily disabling that check while the situation with the metadata
> source gets sorted out, then that ought to be their decision.

I didn't know that the requireValidMetadata flag could be used in this
way. This should probably be documented.

Tom


More information about the dev mailing list