https metadata fetch weirdness after windows SP 3.5.0 update
Peter Schober
peter.schober at univie.ac.at
Thu Mar 27 09:41:19 UTC 2025
Paul B. Henson via users <users at shibboleth.net> [2025-03-27 02:57 CET]:
> I've got a client that is having trouble fetching metadata from an idp
> (https://idp.uvic.ca/idp/shibboleth)
Not what you're asking about but what about the elephant in the room?
That metadata is unsigned and never expires. Maybe you (i.e., your
client) shouldn't be pulling metadata directly from the IDP in the
first place? "If it hurts don't do it." ;)
Note that the IDP in question *is* registered with
http://www.canarie.ca and a part of the Canadian Access Federation
(CAF) which provides signed and expiring metadata for its members.
The IDP is also available via eduGAIN and within InCommon.
So pulling its metadata from the CAF or InCommon MQD servers instead
while validating the signature and enforcing expiration in the
not-too-distant future seems better all around.
Best,
-peter
More information about the users
mailing list