<div dir="ltr"><span style="font-size:13px;font-family:arial,sans-serif">> It means don't give the URL to that metadata to anyone (e.g. an IdP or</span><br style="font-size:13px;font-family:arial,sans-serif">
<span style="font-size:13px;font-family:arial,sans-serif">> Federation Operator) to use "as is" as this will make a proper key</span><br style="font-size:13px;font-family:arial,sans-serif">
<span style="font-size:13px;font-family:arial,sans-serif">> rollover process pretty much impossible.</span><div><span style="font-size:13px;font-family:arial,sans-serif"><br></span></div><div><span style="font-size:13px;font-family:arial,sans-serif">So, this is a warning included in current versions of shibboleth? do you know what version this was implemented?</span></div>
<div><br></div><div style>Is the metadata still valid?</div><div style><br></div><div style>my idp tell me that after im done configuring the SP, I need to give them the generated Metadata. But when I did, they said they never seen this message before. </div>
<div><span style="font-size:13px;font-family:arial,sans-serif"><br></span></div><div><span style="font-size:13px;font-family:arial,sans-serif"><br></span></div><div class="gmail_extra">
<br><br><div class="gmail_quote">On Wed, Mar 27, 2013 at 11:09 AM, Peter Schober <span dir="ltr"><<a href="mailto:peter.schober@univie.ac.at" target="_blank">peter.schober@univie.ac.at</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
* Pax, Christopher <<a href="mailto:pax@njit.edu" target="_blank">pax@njit.edu</a>> [2013-03-27 15:58]:<br>
<div>> I get the following error at the top my<br>
> <a href="http://example.njit.edu/Shibboleth.sso/Metadata" target="_blank">example.njit.edu/Shibboleth.sso/Metadata</a><br>
><br>
> <!--<br>
> This is example metadata only. Do *NOT* supply it as is without review,<br>
> and do *NOT* provide it in real time to your partners.<br>
> --><br>
<br>
</div>I can't find an error message above or anywhere else in your email.<br>
<div><br>
> I repeated the setup with a linux host and could not produce the problem.<br>
<br>
</div>What problem? If the above warning is not displayed on another install<br>
that other install is probably running an earlier release of the<br>
software that did not yet put the warning there.<br>
<div><br>
> Please give me a explanation of what this message is, and how I can<br>
> resolve it?<br>
<br>
</div>It means don't give the URL to that metadata to anyone (e.g. an IdP or<br>
Federation Operator) to use "as is" as this will make a proper key<br>
rollover process pretty much impossible.<br>
<br>
> <Sessions lifetime="28800" timeout="3600" relayState="ss:mem"<br>
> checkAddress="false" handlerSSL="false" cookieProps="http"><br>
<br>
Any specific reasons you don't want HTTP Cookies limited to TLS/SSL?<br>
Otherwise make that cookieProps="https".<br>
-peter<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div><br><br clear="all"><div><br></div>-- <br><font face="'times new roman', serif">Christopher Pax<br>New Jersey Institute of Technology<br>University Information Services<br><a href="mailto:christopher.pax@njit.edu" target="_blank">christopher.pax@njit.edu</a></font><br>
</div></div>