metadata generation

Nate Klingenstein ndk at internet2.edu
Fri Jun 20 14:44:25 EDT 2014


One reason for that is trust: Pulling unsigned XML over the network in
order to bootstrap technical trust in the contained keys and endpoints
requires insight into the https code and trust path validation of the
metadata consumer. Siging (xmldsig) metadata instead of relying on the
transport doesn't suffer from this, at the cost of the metadata
producer learning how to do that and implement it.

Well, the metadata handler can sign metadata, too, so I think these are separate if related issues.

The other key rollover, where sometimes you'd like published metadata
to differ from the internal software configuration in key aspects (pun
intended). That could probably be also handled by changing the
software to become aware of what is the old key and what is the new
key, but that's not in the package today.

Yes, that's a very good point.

I don't know if "Various Metadata Content" added in 2.4's generator includes KeyInfo, and I bet you could do something ugly with a metadata template, but if you're even thinking about doing any of these things, it will be way easier for you to just host a real metadata file.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20140620/ecf4628e/attachment.html 


More information about the users mailing list