Shibboleth installation clarification

Tom Scavo trscavo at gmail.com
Fri Feb 3 16:34:53 EST 2017


On Fri, Feb 3, 2017 at 4:28 PM, Karla Borecky <kborecky at smith.edu> wrote:
>
> This is what I have in my metadata-providers file -
>
> <!-- Hathitrust - get from InCommon -->
>
> <MetadataProvider id="hathitrust"
> xsi:type="FileBackedHTTPMetadataProvider"
> metadataURL="http://md.incommon.org/InCommon/InCommon-metadata.xml"
> backingFile="/opt/shibboleth-idp/metadata/InCommon-metadata.xml"/>

That is not secure since it does not verify the signature and validate
the expiration date (validUntil) on the XML file. See:
https://spaces.internet2.edu/x/XAQjAQ

Tom


More information about the users mailing list