Signing metadata

Cantor, Scott cantor.2 at osu.edu
Wed Jun 21 12:30:48 EDT 2017


On 6/21/17, 12:20 PM, "users on behalf of Larissa Riedel" <users-bounces at shibboleth.net on behalf of larissa.riedel88 at gmail.com> wrote:

> I'm aware of how metadata is usually created. I've also already used the XMLSecTool to sign metadata of an example
> federation.

Then you've answered your question: that's how it's supposed to work.

> The scenario consists of a single IdP and a single SP with both not being in a federation. I'm trying to distribute the metadata
> (automatically signed) in both directions via https. 

There is no support in either case for that.

> On the SP side it's possible to sign the metadata with the signing attribute of the MetadataGenerator. 

It is possible and is wrong. That only works if you generate the metadata and doing so will break the other system if the configuration changes because there is no gap between the time of the change and the time the metadata is updated. That gap is an absolute requirement for this to be worth doing.

> Is there any equivalent way to automatically sign the metadata for the IdP?

No, and the SP feature is not meant to be used that way.

-- Scott




More information about the users mailing list