6 Hour validUntil in IdP 3.4.0 Metadata Generator
Nate Klingenstein
ndk at sudonym.me
Mon Oct 29 10:55:52 EDT 2018
Rod,
> This is probably better targeted at the dev list but anyway..
>
I never know where exactly to draw the line since this isn't really a bug
nor a code issue, just something that I'm observing tripping up a large
proportion of testers who seem to abandon the effort at that point.
There are 14 IdP's with expired IdP metadata in SAMLtest within the last
week, and I think that will grow as there are more fresh 3.4.0 installs.
For now, I added some bolded text to the upload page informing users they
need to make sure they check validUntil.
(Channelling Scott): One could argue that the change is then having the
> required effect [1]
>
> "Part of my thought was that to such a system or person, it's a
> clear signal that the submitter likely did nothing in
> the way of review or thought behind providing it."
This is just a fundamental difference of opinion. From teaching all the
Installfests, I found that people were much more successful in learning
complex concepts when they could approach each task individually and
iteratively. This adds metadata(not just as an idea, but as something they
actively have to grok and change) to the list of things a deployer will
need to understand before they can even get to a login page, and I'm
concerned about the impact on adoption. Non-Shibboleth IdP's are getting
through the testing phase much more routinely.
At the very least, it would be nice to note metadata modification in the
typical next steps on the Installation page, because the deployer is going
to have to either write their own metadata or modify the example before
they can interact with any SP that follows the standards.
https://wiki.shibboleth.net/confluence/display/IDP30/Installation
I'd also suggest that having metadata which is going to break someone's
> installation in a couple of weeks is probably worse than having one which
> breaks while you have the task swapped in.
>
I would concur, but I was just looking for compromises and would have
suggested something in the range of a year with a WARN in the IdP's own
logs when the expiration date is within a few months.
Thanks for taking the time to explain,
Nate.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20181029/afde73f7/attachment.html>
More information about the users
mailing list