Metadata did not include a validUntil attribute
Lipscomb, Gary
glipscomb at csu.edu.au
Mon Nov 6 20:36:48 EST 2017
Hi Scott,
I had downloaded it manually and loaded it in with our external vendor metadata. All work well until the validUntil date arrived then no-one could access the site. I was looking at a way to overcome this without removing the validUntil attribute from the metadata.
The other issue then is how do I know if the SP has made changes to their metadata e.g. end points etc.
Regards
Gary
> -----Original Message-----
> From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Cantor,
> Scott
> Sent: Tuesday, 7 November 2017 12:29
> To: Shib Users <users at shibboleth.net>
> Subject: Re: Metadata did not include a validUntil attribute
>
> On 11/6/17, 8:22 PM, "users on behalf of Lipscomb, Gary" <users-
> bounces at shibboleth.net on behalf of glipscomb at csu.edu.au> wrote:
>
> > I'm trying to download metadata from PageUpPeople and keep on getting
> > the above error. The metadata appears to have a validUntil date set.
>
> Not at the root. The filter probably only accepts the attribute on the root
> element.
>
> You should not remotely load metadata from vendors, that's ill-advised at
> best and a security exposure at worst. You definitely can't treat it as though
> it's adhering to the profiles and trust models used by federations that expect
> validUntil enforcement.
>
> -- Scott
>
>
> --
> For Consortium Member technical support, see
> https://wiki.shibboleth.net/confluence/x/coFAAg
> To unsubscribe from this list send an email to users-
> unsubscribe at shibboleth.net
More information about the users
mailing list