Best Practices for Metadata Management

Tom Scavo trscavo at gmail.com
Mon May 28 11:51:42 EDT 2018


At one point Scott suggested we might need a guide to best practices
for metadata management, something that summarized the uses and
advantages of various metadata providers, at least for IdP deployers.
(That's my recollection anyway, I can't find the original comment.)

I created a new document in the wiki that outlines a set of best
practices for IdP deployers. [1] Here's a brief critique of my own
work:

- Thanks to LocalDynamicMetadataProvider, I think we have a pretty
good story for local metadata. (Whether or not I hit the mark is an
open question.) All we need now are tools for deployers.

- The story surrounding remote metadata is incomplete. I don't know
what else to say. How do we mitigate the risk associated with
DynamicHTTPMetadataProvider?

- The use of entity attributes to drive automated relying party
configuration (a so-called metadata-driven configuration) is critical.
Scott has already written the definitive document on the subject. [2]

All comments are welcome of course.

Tom

[1] https://wiki.shibboleth.net/confluence/x/JQXKAg
[2] https://wiki.shibboleth.net/confluence/x/VQC_AQ


More information about the dev mailing list