Certificate in IDP metadata xml file

Rod Widdowson rdw at steadingsoftware.com
Sat Dec 17 10:54:26 GMT 2011


Ajay,
Briefly, No.

Metadata is transportable (it is your statement about your IdP which other entities will save and consult), so specifying a file:
type URL (even if it was allowed) would not work.  With one unimportant edge case exception, the metadata is of no interest to the
IdP.

In a usual deployment the IdP cert will be extremely slowly changing so the cost of cut and pasting the certificate into your
metadata file will not be a burden.

Rod

> -----Original Message-----
> From: users-bounces at shibboleth.net [mailto:users-bounces at shibboleth.net] On Behalf Of ajay bhadauria
> Sent: 17 December 2011 04:10
> To: users at shibboleth.net
> Subject: Certificate in IDP metadata xml file
> 
> Hi,
> 
> I am new to the shibboleth IDP. I wanted to know that can I give the location of idp
> certificate(/shibboleth/cert/idp.cert) in idp-metadata.xml file as below  ?
> 
> <ds:X509Certificate>
>          file:///shibboleth/cert/idp.cert
>  </ds:X509Certificate>
> 
> Thanks
> Ajay




More information about the users mailing list