SP upgrade 2.3.1 to 2.4.3: disable signature validation of xml metadata?

Jacob Lundberg jacob at collegenet.com
Mon Jun 17 19:41:38 EDT 2013


On Mon, 2013-06-17 at 21:04 +0000, Cantor, Scott wrote:
> https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPTransportOption

Genius.  I think it is working.  While I was at it, I added whitelist
filters so at least they can't muck around with other entities.

<MetadataProvider type="XML" uri="https://host.com/path/to/metadata.xml" backingFilePath="metadata-host.xml" reloadInterval="7200">
  <MetadataFilter type="Whitelist"><Include>https://host.com/entityId</Include></MetadataFilter>
  <TransportOption provider="CURL" option="64">1</TransportOption>
  <TransportOption provider="CURL" option="81">2</TransportOption>
  <TransportOption provider="CURL" option="10065">/etc/ssl/certs/ca-certificates.crt</TransportOption>
</MetadataProvider>

BTW we are members of InCommon.  In fact we have the dubious honor of
having more endpoints in InCommon's metadata than anyone else.  We agree
about using federations and try to get all our clients to join up.  Some
do but for various reasons some refuse to.

Thanks for the help,
-Jacob

-- 

Jacob Lundberg
Director, IT Services
jacob at collegenet.com
503.290.0100 (voice)
503.973.5252 (fax)
503.901.8343 (cell)



More information about the users mailing list