client authenticated IdP metadata
Cantor, Scott
cantor.2 at osu.edu
Thu Apr 26 09:13:07 EDT 2018
> Inadvised for security reasons or because it's hard to get working?
It's entirely untested, probably not stable, and serves no purpose. If anything it's a red flag that the person expecting to "protect" their metadata probably doesn't know what they're doing.
I've heard of rare cases where people "generate" per-customer metadata based on authenticating the customer but since I'd never trust a one-off source of metadata like that anyway, it's moot.
-- Scott
More information about the users
mailing list