<div dir="ltr"><br><div class="gmail_extra"><br><div class="gmail_quote">On Mon, Mar 30, 2015 at 7:11 AM, Peter Schober <span dir="ltr">&lt;<a href="mailto:peter.schober@univie.ac.at" target="_blank">peter.schober@univie.ac.at</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">* Tom Scavo &lt;<a href="mailto:trscavo@gmail.com">trscavo@gmail.com</a>&gt; [2015-03-30 14:44]:<br>
<span class="">&gt; &gt; I don&#39;t use InCommon for on-campus systems, and I don&#39;t supply the<br>
&gt; metadata for our IdP to them with it. I host the metadata file, but<br>
&gt; I also sign it every morning, and it expires every few days, and the<br>
&gt; (Shibboleth) SPs check all of that when they load it every few<br>
&gt; hours.<br>
&gt;<br>
&gt; Hopefully, soon, you (and others) won&#39;t have to do that any more:<br>
&gt;<br>
&gt; <a href="http://mdq-beta.incommon.org/global/entities/urn%3Amace%3Aincommon%3Aosu.edu" target="_blank">http://mdq-beta.incommon.org/global/entities/urn%3Amace%3Aincommon%3Aosu.edu</a><br>
<br>
</span>You&#39;d still have to point them elsewhere and explain to them why they<br>
should trust any output from that, same as with an aggregate that gets<br>
filtered after downloading (whether it&#39;s your own or a federation&#39;s).<br></blockquote><div><br></div><div>It&#39;s not that hard to get them to point elsewhere especially when they don&#39;t get a choice in the matter. </div><div><br></div><div>Dave</div><div><br></div></div>-- <br><div class="gmail_signature">David Langenberg<div>Identity &amp; Access Management</div><div>The University of Chicago</div></div>
</div></div>