6 Hour validUntil in IdP 3.4.0 Metadata Generator

Nate Klingenstein ndk at signet.id
Sat Oct 27 17:40:43 EDT 2018


All,

 
Performing a fresh install of 3.4.0 appears to generate example metadata with a validUntil that is 6 hours from the instant of installation, e.g. validUntil="2018-10-27T20:25:54.617Z" from an install I just performed.  I presume this is the implementation of:

 
https://issues.shibboleth.net/jira/browse/IDP-1118

 
I can understand putting in a default expiration of several months, which would give deployers time to learn how to manage and write metadata while still imposing a deadline for doing it, but 6 hours means the deployer needs to almost immediately understand and modify their metadata before even testing interoperability.

 
This is causing numerous Shibboleth IdP testers at SAMLtest.id to encounter failures due to metadata that is already expired by the time they upload it.  I would rather not have to set requireValidMetadata to false.

 
Is there any chance of giving deployers a longer grace period?

 
Thanks,

Nate.

 
 
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20181027/818a2799/attachment.html>


More information about the users mailing list