Our Info Security folks want a new IDP URL
Cantor, Scott
cantor.2 at osu.edu
Fri Oct 26 18:15:26 EDT 2018
On 10/26/18, 5:07 PM, "users on behalf of Losen, Stephen C (scl)" <users-bounces at shibboleth.net on behalf of scl at virginia.edu> wrote:
> By "not be broken and use metadata" do you mean periodically fetch the IDP metadata automatically? We have many
> SPs that installed a local copy of our IDP metadata file once and are not configured to refresh. Do you consider this
> "broken" ?
And insecure, yes, at least without a defined process to deal with revocation manually.
-- Scott
More information about the users
mailing list