metadata generation
Cantor, Scott
cantor.2 at osu.edu
Fri Jun 20 14:55:57 EDT 2014
On 6/20/14, 2:48 PM, "Jeff Masiello" <jmasiello at actionet.com> wrote:
>So I should, for the IdP, create a location that just has a build MD file
>and have the SP¹s grab that as they spin up? I guess my next question is,
>and I haven¹t
> read all the helpful links sent to me yet, is what, if any, are the
>security ramifications of allowing essentially open access to the
>metadata file?
None, but that file needs to be signed, and you need to address the
exchange of that signing key, and other issues like the metadata validity
and key revocation. [1].
If that all looks complex, that's why we use federations.
All of this depends on the relationships between the IdP and the SP
operators. Trust is contextual.
-- Scott
[1] https://wiki.shibboleth.net/confluence/display/SHIB2/TrustManagement
More information about the users
mailing list