SAManage with Shibboleth 3?
Tom Scavo
trscavo at gmail.com
Wed Apr 18 11:53:33 EDT 2018
On Wed, Apr 18, 2018 at 11:01 AM, Cantor, Scott <cantor.2 at osu.edu> wrote:
>> Looking at the external doc you provided earlier, [1] I see that SP metadata
>> can be retrieved via HTTPS.
>
> With no expiration, so that's inherently unable to safely support revocation. And it likely won't be modified in a manner that allows a key change to happen safely, which defeats the purpose of doing it.
As mentioned previously in the thread, there is no certificate in SP
metadata, so there is nothing to revoke. The metadata is dead simple:
https://edin.samanage.com/saml/metadata
Mark, this begs the question: The online metadata contains an
<md:NameIDFormat> element, so I wonder why that is not working for
you. Did you include this element in your snapshot in the file system?
If so, then it should Just Work (TM).
> I would never pull in a third party metadata source outside of InCommon or another similarly managed source, at least absent other assumptions that I have never seen a vendor meet.
I'll come back to this after Mark has successfully integrated with the
SP. I don't want to derail the thread, at least not yet ;-)
Tom
More information about the users
mailing list