Signing metadata

Peter Schober peter.schober at univie.ac.at
Wed Jun 21 14:04:48 EDT 2017


* Cantor, Scott <cantor.2 at osu.edu> [2017-06-21 19:39]:
> > To verify my understanding: The usual way would be that the
> > "federation" retrieves the static metadata of all SPs and IdPs
> > every X hours, verifies each of them and then creates the
> > federation metadata file and sign it?
> 
> Most federations rely on a manual process of operators registering
> changes to their metadata via strongly authenticated access. The
> propagation of the changes is automated, not the receipt of the
> changes.

Right. There may be federations doing this differently but I never
poll/pull from registered entities. There may not even be a URL to
poll, e.g. when the software used doesn't support generating SAML 2.0
metadata.  Even if it did support that it would be missing much of
what makes it useful (extensions and amendments added by the
federation operator) which either cannot be added to the entity's
implementation or where this would make no sense or wouldn't be
sufficiently meaningful/secure, e.g. entity categories (i.e., Entity
Attributes) that are not defined to be self-asserted.
-peter


More information about the users mailing list