client authenticated IdP metadata

Cantor, Scott cantor.2 at osu.edu
Thu Apr 26 09:13:07 EDT 2018


> Inadvised for security reasons or because it's hard to get working?

It's entirely untested, probably not stable, and serves no purpose. If anything it's a red flag that the person expecting to "protect" their metadata probably doesn't know what they're doing.

I've heard of rare cases where people "generate" per-customer metadata based on authenticating the customer but since I'd never trust a one-off source of metadata like that anyway, it's moot.

-- Scott



More information about the users mailing list