How to set the SP metadata expiration date
Cantor, Scott
cantor.2 at osu.edu
Thu Oct 18 14:59:15 EDT 2012
On 10/18/12 2:14 PM, "Yaowen Tu" <yaowen.tu at gmail.com> wrote:
>
>1) As you suggested, I read the SAML spec. In saml-metadata-2.0-os.pdf,
>when describing the <EntitiesDescriptor> and <EntityDescriptor> element,
>I found this sentense:
> When used as the root element of a metadata instance, this
>element MUST contain either a validUntil
>or cacheDuration attribute.
> Does it mean in the metadata, the root <EntityDescriptor> needs to
>include "validUntil"? Why you said it is optional?
Well, it says one or the other. The real answer is, it depends. Depends on
your trust model, your metadata exchange model, etc. You have to supply
all the context, or you're asking us to guess what you're thinking of
doing.
The wiki discusses the trust implications of different models of metadata
exchange in the Metadata topic (or a sub page of that).
>2) If I want to use Shibboleth SP. How can I produce a production level
>metadata file? Do I need to manually edit it based on what ever Shib SP
>has generated?
You should, yes. You can't use metadata properly if it's limited to only
what the SP produces or if it's tightly derived from the running
configuration. Key rollover is not feasible for example.
-- Scott
More information about the users
mailing list