Recommended or "Best" Practices for Shibboleth IdP?

Peter Schober peter.schober at univie.ac.at
Fri Oct 2 15:17:28 UTC 2020


* Mak, Steve <makst at upenn.edu> [2020-10-02 17:09]:
> Here's how we structure our SP metadata so we don't generally need
> to touch metadata-providers.xml, resolver, or filter unless people
> need custom work:

Thanks. For any parts of that setup that are not covered by examples
in the documentation that would make a fine addition, I think.

> We don't have a single vendor that that is integrated through a
> remote URL metadata provider. Even if a vendor did that, I'd still
> just pull down the file and install it locally.

One thing I'd add would be committing the downloaded metadata (before
curation/editing) to git as well and then re-downloading and diff'ing
that regularly, as a kind of warning system about not communicated
metadata changes. After review (and potentially carryinf over whatever
needs changing to your curated version) commit the changed version
again to silence any alarms.

-peter


More information about the users mailing list