SP will not provide metadata file: maybe it's not necessary?

Eric Goodman Eric.Goodman at ucop.edu
Tue Aug 2 13:01:01 EDT 2016


>> This vendor implies that an SP metadata file is not necessary.

>Strictly speaking, that is true. The SAML spec does not mandate the use of metadata.

And it's product specific whether they can even leverage it. Many (non-Shib) products that are able to consume SAML assertions are unable to consume metadata; their configuration is frequently via UI that where you manually enter ACS endpoints and upload signing (verification) certs. Even when they get your IdP's information from InCommon, they might be literally loading it up in an XML editor and copying and pasting the important bits out. 

So for *them* (and their limited software implementations) the metadata has no practical value other than as a very formalized list of the information they need (entity ID, SSO endpoint, nameid format, certs). They just build manual maintenance of every client's IdP configuration into the way they do their work.

--- Eric




More information about the users mailing list