Is there a checklist for the metadata file?

Tom Scavo trscavo at gmail.com
Sun Mar 29 18:19:08 EDT 2015


On Sun, Mar 29, 2015 at 5:17 PM, Joe Edwards <joee at uw.edu> wrote:
>
> 'This is example metadata only.
>   Do *NOT* supply it as is without review,...'
>
> Is there a checklist to help ensure that all the elements
> required to complete the metadata are included?

I've been trying to squash this PoV for the last six months or so, but
without much luck. Your metadata file should not mirror your
deployment, it should tell your SP partner how you want to
interoperate with it. Most published metadata files expose way too
many possibilities, all which need to be interoperable and secure.
Pick the bare minimum and go with that.

> Is it possible to have https://myidp.edu/idp/shibboleth
> return a complete metadata file?

That's exactly what you don't want to do.

> If best practice is to review and revise idp-metadata.xml
> and provide that file to SP's, I'll go along with that.

Well, if you're sharing metadata files bilaterally, frankly you're
doing it wrong. Either join a federation, or if that's not possible,
publish your file at a well-known location. Something like
https://reep.refeds.org/ might be better than trying to maintain a
location yourself (which has security implications).

Tom


More information about the users mailing list