<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; color: rgb(0, 0, 0); font-size: 14px; font-family: Calibri, sans-serif; ">
<div>
<div>
<div>Ok, so I've got a partner using MS ADFS for their SAML support. They are busy following the MS documents on integration including using a MetadataFilter for SignatureValidation. Ok, fair enough. So I'm going through the wiki to make sure what they are
 asking will work, etc.</div>
<div><br>
</div>
<div>Now, here's my question. Their request is for me to load their metadata file from a URL. So if I do that, it does seem reasonable to validate the metadata file signature using the signature validation filter. However, I don't really want to load their
 metadata file dynamically, I don't want my system being dependent on their system. So if I do my normal file based load of their metadata, what purpose does signature validation serve?</div>
<div><br>
</div>
<div>thanks,</div>
<div><br>
</div>
<div>Paul</div>
<div><br>
</div>
<div>
<div>
<div>--&nbsp;</div>
<div><br>
</div>
</div>
<div>
<div>Paul Hethmon</div>
<div>Chief Software Architect</div>
<div>Clareity Security, LLC</div>
<div>o) 865.824.1350</div>
<div>c) 865.250.3517</div>
<div>e) paul.hethmon@clareitysecurity.com</div>
</div>
<div><br>
</div>
</div>
</div>
</div>
</body>
</html>