Use of metadata signature filter
Paul Hethmon
paul.hethmon at clareitysecurity.com
Tue Feb 14 16:30:57 GMT 2012
On 2/14/12 11:26 AM, "Cantor, Scott" <cantor.2 at osu.edu> wrote:
>> Now, here's my question. Their request is for me to load their metadata
>>file
>> from a URL. So if I do that, it does seem reasonable to validate the
>>metadata
>> file signature using the signature validation filter. However, I don't
>>really
>> want to load their metadata file dynamically, I don't want my system
>>being
>> dependent on their system. So if I do my normal file based load of their
>> metadata, what purpose does signature validation serve?
>
>Technically with backup files and non-failfast behavior, you're not
>really dependent on them unless you mean in the sense of them breaking
>things by changing the metadata wrongly. I guess it depends how much you
>expect to prevent that yourself by reviewing any changes.
>
>
Well, I've been bitten one too many times by partners who give me bad
metadata files. I don't really care if they give me garbage values per se,
but I definitely don't want Shib to fail because they give me garbage xml.
My phone is the one that rings at that point, not theirs.
Paul
More information about the users
mailing list