https metadata fetch weirdness after windows SP 3.5.0 update

Paul B. Henson henson at acm.org
Fri Mar 28 05:02:11 UTC 2025


On 3/27/2025 2:41 AM, Peter Schober via users wrote:

> Not what you're asking about but what about the elephant in the room?

Elephant you say? You mean that really quiet one sitting the corner 
minding its own business? But but but I was asked to take a look at this 
hyperactive squirrel running all around the room making a nuisance of 
itself ;)...

I confess that sometimes when I'm wearing my consultant hat I can 
overly focus specifically on the problem I was brought and not remember 
to take a step back and consider the overall picture :(. Thanks for 
pulling my blinders off in this instance, your suggestion both removes 
the SSL issue from the table and is simply a better implementation as well.

>    So pulling its metadata from the CAF or InCommon MQD servers instead
> while validating the signature and enforcing expiration in the
> not-too-distant future seems better all around.

They are having the same problem with a dev instance from that 
organization at idppreprod.uvic.ca, unfortunately (but not surprisingly) 
that one doesn't appear to be in any federation.

As a dev instance associated with a dev SP, it still a bad practice but 
not quite as critical to directly consume the metadata. I'll ask them if 
they could find a better way to get it, but ideally I would still like 
to sort out what is causing the SP SSL failures to their servers. If 
only to satisfy my own curiosity :). I'm guessing they are running an 
old web server, my client is going to ask them about that and see if 
they can update it.



More information about the users mailing list