metadata management tools

Cantor, Scott cantor.2 at osu.edu
Tue Aug 30 15:54:29 BST 2011


On 8/30/11 10:30 AM, "Liam Hoekenga" <liamr at umich.edu> wrote:
>
>..but that's really strictly for SP management.  We're looking for
>something to help take this SP-only metadata file and wrap with the
>"rest" 
>of the rest of the federation metadata (IdP information, certificates,
>expiration, etc).

I don't see the connection. The SP metadata is for the IdP to consume, and
the SPs themselves don't need any of that.

For provisioning IdPs, I'm currently using InCommon metadata directly. As
part of a SAML 2 transition, I'm going to shift back to locally published
IdP metadata alongside it, but that's really a one time thing, plus the
scripting to sign it every day or whatever. Not much to it really.

I will probably take advantage of the newer SP features in support of CRLs
to emulate SWITCH, and put the root key offline to minimize the risks
associated with online signing.

-- Scott



More information about the users mailing list