<div dir="ltr">Hi Scott,<br><div class="gmail_extra"><div class="gmail_extra"><br></div><div class="gmail_extra">thanks for the help! So generating and signing the metadata on the fly is only feasible for testing environments and in production environments the SP and IdP Metadata should be distributed from static files?</div><div class="gmail_extra"><br></div><div class="gmail_extra">Would you mind giving me a more in depth explanation why that gap is necessary? Unfortunately I don't understand the reasoning.</div><div class="gmail_extra"><br></div><div class="gmail_extra">To verify my understanding: The usual way would be that the "federation" retrieves the static metadata of all SPs and IdPs every X hours, verifies each of them and then creates the federation metadata file and sign it?</div><div class="gmail_extra"><br></div><div class="gmail_extra">Larissa</div><div class="gmail_extra"><br></div><div class="gmail_extra"><br></div><div class="gmail_extra"><br></div></div></div>