Recommended or "Best" Practices for Shibboleth IdP?

Cantor, Scott cantor.2 at osu.edu
Fri Oct 2 14:56:48 UTC 2020


On 10/2/20, 10:36 AM, "users on behalf of Donald Lohr" <users-bounces at shibboleth.net on behalf of lohrda at jmu.edu> wrote:

>    So how do you handle "making" a vendor change their metadata to include 
>    a cert for signing and the validUntil setting, especially when your 
>    Senior management is dictating that a badly designed application be 
>    added to your Shibboleth service?

I don’t, that's why I don't rely on remote metadata in general. I curate their metadata so I can protect the security and reliability of my system.

You have to bear in mind that modulo a rounding error, there's Shibboleth and there's everything else when it comes to metadata. Vendors are not by and large outside of education sector exposed to anything but non-working IdPs without any way to change endpoints ot keys without manual effort. So their change processes either don't exist or are manual. Metadata is the tail, not the dog. So the idea that using their metadata will "save me effort" just doesn't really apply.

-- Scott




More information about the users mailing list