metadata generation

Peter Schober peter.schober at univie.ac.at
Fri Jun 20 15:10:06 EDT 2014


* Nate Klingenstein <ndk at internet2.edu> [2014-06-20 20:44]:
> Well, the metadata handler can sign metadata, too, so I think these
> are separate if related issues.

I think pulling (unsigned) metadata from the generator once, while
making sure TLS is fine (as far as that's possible today) will be
sufficient for most deployments.
If all SP admins have credentials at the IDP, having a simple
authenticated "dump your XML here" form would seem like a sensible
next step, rather than configuring one verification certificate for
every SP into your IDP (which would require auto-reloading the IDP's
relying-party.xml or restarting the IDP after each new SP has been
added).
-peter


More information about the users mailing list