Use of metadata signature filter

Paul Hethmon paul.hethmon at clareitysecurity.com
Tue Feb 14 16:30:57 GMT 2012


On 2/14/12 11:26 AM, "Cantor, Scott" <cantor.2 at osu.edu> wrote:


>> Now, here's my question. Their request is for me to load their metadata
>>file
>> from a URL. So if I do that, it does seem reasonable to validate the
>>metadata
>> file signature using the signature validation filter. However, I don't
>>really
>> want to load their metadata file dynamically, I don't want my system
>>being
>> dependent on their system. So if I do my normal file based load of their
>> metadata, what purpose does signature validation serve?
>
>Technically with backup files and non-failfast behavior, you're not
>really dependent on them unless you mean in the sense of them breaking
>things by changing the metadata wrongly. I guess it depends how much you
>expect to prevent that yourself by reviewing any changes.
>
>

Well, I've been bitten one too many times by partners who give me bad
metadata files. I don't really care if they give me garbage values per se,
but I definitely don't want Shib to fail because they give me garbage xml.
My phone is the one that rings at that point, not theirs.

Paul



More information about the users mailing list