<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body text="#000000" bgcolor="#FFFFFF">
<p>Hi Tom,</p>
<p>by default the validity of the metadata should be checked?</p>
<p>
<blockquote type="cite"><a class="moz-txt-link-freetext" href="https://wiki.shibboleth.net/confluence/display/IDP30/MetadataConfiguration#MetadataConfiguration-AttributesAttributes">https://wiki.shibboleth.net/confluence/display/IDP30/MetadataConfiguration#MetadataConfiguration-AttributesAttributes</a><br>
<br>
<p>requireValidMetadata</p>
<table class="wrapped confluenceTable">
<tbody>
<tr>
<td class="confluenceTd"><br>
</td>
<td colspan="1" class="confluenceTd">Boolean</td>
<td class="confluenceTd">true</td>
<td class="confluenceTd">
<p>Whether candidate metadata found by the resolver must
be valid in order to be returned (where validity is
implementation specific, but in SAML cases generally
depends on a <code>validUntil</code> attribute.) If
this flag is true, then invalid candidate metadata
will not be returned.</p>
</td>
</tr>
</tbody>
</table>
</blockquote>
</p>
<p>So, if we understand the documentation correct, it's only a
additional check?</p>
<p>
<blockquote type="cite"><a class="moz-txt-link-freetext" href="https://wiki.shibboleth.net/confluence/display/IDP30/RequiredValidUntilFilter">https://wiki.shibboleth.net/confluence/display/IDP30/RequiredValidUntilFilter</a><br>
<br>
<span>The value of the <code>validUntil</code> attribute is too
far into the future as specified by the <code>maxValidityInterval</code>
attribute.</span></blockquote>
</p>
<p>Right?<br>
</p>
With nice regards.<br>
Martin<br>
<br>
<div class="moz-cite-prefix">Am 25.04.2018 um 08:38 schrieb Martin
Lunze:<br>
</div>
<blockquote type="cite"
cite="mid:d2bd39db-c2ac-5221-605b-4c1df559d6af@tu-dresden.de">Hello
Tom,
<br>
<br>
thanks for your hint too.
<br>
<br>
This was unintentional.
<br>
I will talk to the guys of the DFN-AAI, maybe they will add this
line to their documentation.
<br>
<br>
With nice regards.
<br>
Martin
<br>
<br>
<br>
Am 24.04.2018 um 16:37 schrieb Tom Scavo:
<br>
<blockquote type="cite">Hi Martin,
<br>
<br>
On Tue, Apr 24, 2018 at 9:50 AM, Martin Lunze
<br>
<a class="moz-txt-link-rfc2396E" href="mailto:martin.lunze@tu-dresden.de"><martin.lunze@tu-dresden.de></a> wrote:
<br>
<blockquote type="cite"><MetadataProvider
id="DFN-AAI-EduGain"
<br>
xsi:type="FileBackedHTTPMetadataProvider"
<br>
backingFile="%{idp.home}/metadata/DFN-AAI-edugain-metadata.xml"
<br>
<br>
metadataURL=<a class="moz-txt-link-rfc2396E" href="https://www.aai.dfn.de/fileadmin/metadata/dfn-aai-edugain+sp-metadata.xml">"https://www.aai.dfn.de/fileadmin/metadata/dfn-aai-edugain+sp-metadata.xml"</a>
<br>
maxRefreshDelay="PT2H">
<br>
<br>
<MetadataFilter xsi:type="SignatureValidation"
requireSignedRoot="true"
<br>
certificateFile="/etc/apache2/ssl.crt/dfn-aai.g2.pem"/>
<br>
<MetadataFilter xsi:type="EntityRoleWhiteList">
<br>
<RetainedRole>md:SPSSODescriptor</RetainedRole>
<br>
</MetadataFilter>
<br>
<MetadataFilter xsi:type="EntityAttributes">
<br>
<saml:Attribute
<br>
Name=<a class="moz-txt-link-rfc2396E" href="https://tu-dresden.de/entity-type">"https://tu-dresden.de/entity-type"</a>
<br>
NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
<br>
<br>
<saml:AttributeValue><a class="moz-txt-link-freetext" href="https://tu-dresden.de/entity-type/external/edugain">https://tu-dresden.de/entity-type/external/edugain</a></saml:AttributeValue>
<br>
</saml:Attribute>
<br>
<ConditionRef>always-true</ConditionRef>
<br>
</MetadataFilter>
<br>
</MetadataProvider>
<br>
</blockquote>
I don't have an answer to your question but I wanted to ask: Did
you
<br>
intentionally omit a RequiredValidUntil filter or was that
<br>
intentional?
<br>
<br>
Cheers,
<br>
<br>
Tom
<br>
</blockquote>
<br>
</blockquote>
<br>
<pre class="moz-signature" cols="72">--
Martin Lunze
IT-Systemadministrator
Technische Universität Dresden
Zentrum für Informationsdienste und Hochleistungsrechnen (ZIH)
Operative Prozesse und Systeme (OPS)
01062 Dresden
Tel.: +49 (351) 463-35881
E-Mail: <a class="moz-txt-link-abbreviated" href="mailto:martin.lunze@tu-dresden.de">martin.lunze@tu-dresden.de</a></pre>
</body>
</html>