failed signature verification causing IdP not to load?

Rob Gorrell rwgorrel at uncg.edu
Fri Jun 12 12:17:13 EDT 2015


Scott,

Is it true that even with failFastInitialization="false", that one bad
apple in that particular metadata provider will continue to spoil the
bunch? what i'm noticing with this setting, while my IdP now loads and
processes requests normally from other metadata providers, that all
requests to the metadata provider with the bad entity fail... even the ones
that are good.

So is it correct that failing a signature validation on one entity will
spoil things for the rest of the entity's in that same metadata provider?

-Rob


On Fri, Jun 12, 2015 at 11:28 AM, Cantor, Scott <cantor.2 at osu.edu> wrote:

> On 6/12/15, 11:23 AM, "users on behalf of Rob Gorrell" <
> users-bounces at shibboleth.net on behalf of rwgorrel at uncg.edu> wrote:
>
> >So we don't have that property defined on our MetadataProvider which
> aligns with the default value being true.
>
> I lost that particular argument. You will notice that the
> idp.service.*.failFast properties in V3 have a different default.
>
> -- Scott
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>



-- 
Robert W. Gorrell
Systems Architect, Identity and Access Management
University of NC at Greensboro
336-334-5954
PGP Key ID B36DB0CA
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20150612/b237ada0/attachment.html>


More information about the users mailing list