Contact Information in SP MetadataGenerator

Michael A Grady mgrady at unicon.net
Tue May 22 16:32:20 EDT 2018


> On May 22, 2018, at 2:07 PM, skannappan <skannappan at sae.org> wrote:
> 
> To meet baseline expectations for InCommon Federation, I have to include
> contact information for all my admins. I am however not sure how to use the
> MetadataGenerator to include the following elements in my metadata which can
> be automatically generated using /Shibboleth.sso/Metadata/
> 
> <md:ContactPerson contactType="technical"
> xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata">
> <md:GivenName>Testing</md:GivenName>
> <md:EmailAddress>mailto:test at gmail.com <mailto:test at gmail.com></md:EmailAddress>
> </md:ContactPerson>


What the Shib SP will or will not generate as far as metadata is irrelevant as far as InCommon and Baseline Expectations goes. Because the metadata that InCommon cares about is the metadata that you register with InCommon, using the InCommon Federation Manager wizard. You don't "feed it a file of metadata", you have to use the wizard to generate the appropriate metadata. And that Fed Manager interface fully supports entering all the metadata elements required, including MDUI and Contact elements.

InCommon doesn't care what your SP generates, because no one should be relying on having partners getting the metadata from that SP endpoint. That's not a secure and reliable way to manage metadata. Security, scalability, and reliability is one of the key reasons one registers metadata with InCommon in the first place.

--
Michael A. Grady
IAM Architect, Unicon, Inc.



-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/dev/attachments/20180522/3810f88f/attachment.html>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 874 bytes
Desc: Message signed with OpenPGP
URL: <http://shibboleth.net/pipermail/dev/attachments/20180522/3810f88f/attachment.sig>


More information about the dev mailing list