Automating the generation of IdP metadata

Tom Scavo trscavo at gmail.com
Fri Feb 12 15:42:58 EST 2016


On Fri, Feb 12, 2016 at 2:19 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:
>> So if I understand you correctly I need to open an additional https port on
>> Apache for the ArtifactResolutionService and AttributeService.
>
> No, first you determine whether you need SOAP support [1].
>
> ...
>
> For now, you should simply not bother with the back channel. I very much doubt you need it.

Strong +1

>> Is there any way to modify the 8443 default without editing the auto-
>> generated idp-metadata.xml?
>
> That is a convenience to get people started. Metadata MUST be maintained explicitly to reflect the deployment, changes you make, and how you need to make the changes visible to others. It is meant to be maintained by hand because we provide no tools to do otherwise.

Franck, for starters I recommend you submit your metadata to the
REFEDS REEP registry: https://reep.refeds.org/

IMO that's much better than trying to host it yourself.

>> Also I assume that the SP (or anyone who needs those services) will take the
>> port number from the IDP metadata, so that it's the only place where that
>> port number need to be configure?
>
> They take it from the metadata, but they do not take it from some piece of example metadata and they do not take it from you at all unless they don't understand how this all works. Federations exist to broker trusted metadata between partners. Outside of higher ed, that understanding doesn't exist, but that doesn't mean the problem goes away.

Franck, does your company have ties to higher ed? Are you in the U.S.?
If yes to both, find a higher ed institution to sponsor your company
into InCommon.

Tom


More information about the users mailing list