managing untrusted metadata
Tom Scavo
trscavo at gmail.com
Fri Apr 27 15:30:26 EDT 2018
On Fri, Apr 27, 2018 at 1:28 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:
>
>> Is this running on the IdP server or elsewhere?
>
> My staging system. If you mean the GUI...
No, I'm wondering if there's any value to running this metadata
management system off-IdP. Not for you perhaps but in general.
> As an example, if I made a (poor) decision to push an SP into InCommon that doesn't support encryption, I know I have to work around that and turn it off since they're forced to supply a key that won't actually work.
That's exactly the kind of example I was looking for. Instead of
configuring an exception, one could filter the encryption certificate
from the metadata (assuming the tools exist). Wouldn't that be
preferable?
Taking this to its logical conclusion, most (if not all) integrations
boil down to metadata manipulation. Even attribute release can be
controlled by metadata (add the necessary RequestedAttribute elements
and tag the entity as "locally vetted" or something like that). Is
this a goal?
Tom
More information about the users
mailing list