Metadata "trust"
Christopher Bongaarts
cab at umn.edu
Mon Mar 19 15:39:49 GMT 2012
On 3/14/2012 8:40 PM, Cantor, Scott wrote:
> That said, sure, if you trust the SSL/TLS connection, then you're
> essentially getting the metadata direct from the source, and as long as
> you're willing to trust the peer to tell you anything you want to know
> about the peer, that's fine.
Not to mention that there's nothing precluding the metadata at, say,
www.providerA.com from "accidentally" including bogus data for an
entityID for competitorB.com (this is one of the reasons why
automatically loading metadata, even signed metadata, is risky).
--
%% Christopher A. Bongaarts %% cab at umn.edu %%
%% OIT - Identity Management %% http://umn.edu/~cab %%
%% University of Minnesota %% +1 (612) 625-1809 %%
More information about the users
mailing list