common LDAP schemas to draw attribute definitions from

> I think a lot of our SPs are probably "set it and forget it" kinds of things.  Fortunately, the attributes that use URLs as their names are pretty targeted.

I understand -- painfully -- what you mean.  It's obviously not a show stopper for the attributes, though none of it negates the potential benefits Todd and I mentioned or the rollover scenario.  The bigger issue in your case is that it would be nice to get out of "don't touch it it works" mode, just in case your key did happen to get compromised.

