Metadata did not include a validUntil attribute

Lipscomb, Gary glipscomb at csu.edu.au
Mon Nov 6 20:36:48 EST 2017


Hi Scott,

I had downloaded it manually and loaded it in with our external vendor metadata. All work well until the validUntil date arrived then no-one could access the site. I was looking at a way to overcome this without removing the validUntil attribute from the metadata. 
The other issue then is how do I know if the SP has made changes to their metadata e.g. end points etc.

Regards

Gary

> -----Original Message-----
> From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Cantor,
> Scott
> Sent: Tuesday, 7 November 2017 12:29
> To: Shib Users <users at shibboleth.net>
> Subject: Re: Metadata did not include a validUntil attribute
> 
> On 11/6/17, 8:22 PM, "users on behalf of Lipscomb, Gary" <users-
> bounces at shibboleth.net on behalf of glipscomb at csu.edu.au> wrote:
> 
> > I'm trying to download metadata from PageUpPeople and keep on getting
> > the above error.  The metadata appears to have a validUntil date set.
> 
> Not at the root. The filter probably only accepts the attribute on the root
> element.
> 
> You should not remotely load metadata from vendors, that's ill-advised at
> best and a security exposure at worst. You definitely can't treat it as though
> it's adhering to the profiles and trust models used by federations that expect
> validUntil enforcement.
> 
> -- Scott
> 
> 
> --
> For Consortium Member technical support, see
> https://wiki.shibboleth.net/confluence/x/coFAAg
> To unsubscribe from this list send an email to users-
> unsubscribe at shibboleth.net


More information about the users mailing list