<div dir="ltr">Thanks Scott. I&#39;ll stick to http for the metadata.<br></div><div class="gmail_extra"><br><br><div class="gmail_quote">2014-07-24 16:36 GMT-05:00 Cantor, Scott <span dir="ltr">&lt;<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>&gt;</span>:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div class="">On 7/24/14, 5:27 PM, &quot;Christian Munive&quot; &lt;<a href="mailto:christian.munive@gmail.com">christian.munive@gmail.com</a>&gt; wrote:<br>

&gt;<br>
&gt;My question is: Is this a bad practice?<br>
<br>
</div>Yes. Just use http; you should sign the metadata, have a validUntil value,<br>
and enforce a limit on the validity period. If the SSL isn&#39;t part of the<br>
trust fabric, you shouldn&#39;t use it, it will create confusion, barriers to<br>
getting the metadata, and just generally be a pain.<br>
<br>
Or you can set the disregardSslCertificate flag and turn off the SSL<br>
checking. That is a global setting in V2 due to library limitations.<br>
<span class="HOEnZb"><font color="#888888"><br>
-- Scott<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</font></span></blockquote></div><br></div>