Thanks Scott. I still don't quite understand your comments about "validUntil".<br><br>Can you tell me how should I interpret this sentence in SAML spec: When used as the root element of a metadata instance, this element MUST contain either a validUntil or cacheDuration attribute.<br>
<br>You said it depends on my trust model. Could you please elaborate a little bit more? When it is a "must" and when it is optional? or just give me a simple example?<br><br> I have referred to this wiki:<a href="https://wiki.shibboleth.net/confluence/display/SHIB2/Metadata">https://wiki.shibboleth.net/confluence/display/SHIB2/Metadata</a>, and its sub pages, but I didn't find related discussion.<br>
<br><br>Thanks,<br clear="all">Yaowen<br>
<br><br><div class="gmail_quote">On Thu, Oct 18, 2012 at 11:59 AM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div class="im">On 10/18/12 2:14 PM, "Yaowen Tu" <<a href="mailto:yaowen.tu@gmail.com">yaowen.tu@gmail.com</a>> wrote:<br>
><br>
>1) As you suggested, I read the SAML spec. In saml-metadata-2.0-os.pdf,<br>
>when describing the <EntitiesDescriptor> and <EntityDescriptor> element,<br>
>I found this sentense:<br>
> When used as the root element of a metadata instance, this<br>
>element MUST contain either a validUntil<br>
>or cacheDuration attribute.<br>
> Does it mean in the metadata, the root <EntityDescriptor> needs to<br>
>include "validUntil"? Why you said it is optional?<br>
<br>
</div>Well, it says one or the other. The real answer is, it depends. Depends on<br>
your trust model, your metadata exchange model, etc. You have to supply<br>
all the context, or you're asking us to guess what you're thinking of<br>
doing.<br>
<br>
The wiki discusses the trust implications of different models of metadata<br>
exchange in the Metadata topic (or a sub page of that).<br>
<div class="im"><br>
>2) If I want to use Shibboleth SP. How can I produce a production level<br>
>metadata file? Do I need to manually edit it based on what ever Shib SP<br>
>has generated?<br>
<br>
</div>You should, yes. You can't use metadata properly if it's limited to only<br>
what the SP produces or if it's tightly derived from the running<br>
configuration. Key rollover is not feasible for example.<br>
<span class="HOEnZb"><font color="#888888"><br>
-- Scott<br>
</font></span><div class="HOEnZb"><div class="h5"><br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br>