<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=utf-8">
  </head>
  <body text="#000000" bgcolor="#FFFFFF">
    <p>Hi Tom,</p>
    <p>by default the validity of the metadata should be checked?</p>
    <p>
      <blockquote type="cite"><a class="moz-txt-link-freetext" href="https://wiki.shibboleth.net/confluence/display/IDP30/MetadataConfiguration#MetadataConfiguration-AttributesAttributes">https://wiki.shibboleth.net/confluence/display/IDP30/MetadataConfiguration#MetadataConfiguration-AttributesAttributes</a><br>
        <br>
        <p>requireValidMetadata</p>
        <table class="wrapped confluenceTable">
          <tbody>
            <tr>
              <td class="confluenceTd"><br>
              </td>
              <td colspan="1" class="confluenceTd">Boolean</td>
              <td class="confluenceTd">true</td>
              <td class="confluenceTd">
                <p>Whether candidate metadata found by the resolver must
                  be valid in order to be returned (where validity is
                  implementation specific, but in SAML cases generally
                  depends on a <code>validUntil</code> attribute.) If
                  this flag is true, then invalid candidate metadata
                  will not be returned.</p>
              </td>
            </tr>
          </tbody>
        </table>
      </blockquote>
    </p>
    <p>So, if we understand the documentation correct, it's only a
      additional check?</p>
    <p>
      <blockquote type="cite"><a class="moz-txt-link-freetext" href="https://wiki.shibboleth.net/confluence/display/IDP30/RequiredValidUntilFilter">https://wiki.shibboleth.net/confluence/display/IDP30/RequiredValidUntilFilter</a><br>
        <br>
        <span>The value of the <code>validUntil</code> attribute is too
          far into the future as specified by the <code>maxValidityInterval</code>
          attribute.</span></blockquote>
    </p>
    <p>Right?<br>
    </p>
    With nice regards.<br>
    Martin<br>
    <br>
    <div class="moz-cite-prefix">Am 25.04.2018 um 08:38 schrieb Martin
      Lunze:<br>
    </div>
    <blockquote type="cite"
      cite="mid:d2bd39db-c2ac-5221-605b-4c1df559d6af@tu-dresden.de">Hello
      Tom,
      <br>
      <br>
      thanks for your hint too.
      <br>
      <br>
      This was unintentional.
      <br>
      I will talk to the guys of the DFN-AAI, maybe they will add this
      line to their documentation.
      <br>
      <br>
      With nice regards.
      <br>
      Martin
      <br>
      <br>
      <br>
      Am 24.04.2018 um 16:37 schrieb Tom Scavo:
      <br>
      <blockquote type="cite">Hi Martin,
        <br>
        <br>
        On Tue, Apr 24, 2018 at 9:50 AM, Martin Lunze
        <br>
        <a class="moz-txt-link-rfc2396E" href="mailto:martin.lunze@tu-dresden.de"><martin.lunze@tu-dresden.de></a> wrote:
        <br>
        <blockquote type="cite"><MetadataProvider
          id="DFN-AAI-EduGain"
          <br>
               xsi:type="FileBackedHTTPMetadataProvider"
          <br>
              
          backingFile="%{idp.home}/metadata/DFN-AAI-edugain-metadata.xml"
          <br>
          <br>
metadataURL=<a class="moz-txt-link-rfc2396E" href="https://www.aai.dfn.de/fileadmin/metadata/dfn-aai-edugain+sp-metadata.xml">"https://www.aai.dfn.de/fileadmin/metadata/dfn-aai-edugain+sp-metadata.xml"</a>
          <br>
               maxRefreshDelay="PT2H">
          <br>
          <br>
               <MetadataFilter xsi:type="SignatureValidation"
          requireSignedRoot="true"
          <br>
                  
          certificateFile="/etc/apache2/ssl.crt/dfn-aai.g2.pem"/>
          <br>
               <MetadataFilter xsi:type="EntityRoleWhiteList">
          <br>
                  
          <RetainedRole>md:SPSSODescriptor</RetainedRole>
          <br>
               </MetadataFilter>
          <br>
               <MetadataFilter xsi:type="EntityAttributes">
          <br>
                   <saml:Attribute
          <br>
                       Name=<a class="moz-txt-link-rfc2396E" href="https://tu-dresden.de/entity-type">"https://tu-dresden.de/entity-type"</a>
          <br>
                      
          NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
          <br>
          <br>
<saml:AttributeValue><a class="moz-txt-link-freetext" href="https://tu-dresden.de/entity-type/external/edugain">https://tu-dresden.de/entity-type/external/edugain</a></saml:AttributeValue>
          <br>
                   </saml:Attribute>
          <br>
                   <ConditionRef>always-true</ConditionRef>
          <br>
               </MetadataFilter>
          <br>
          </MetadataProvider>
          <br>
        </blockquote>
        I don't have an answer to your question but I wanted to ask: Did
        you
        <br>
        intentionally omit a RequiredValidUntil filter or was that
        <br>
        intentional?
        <br>
        <br>
        Cheers,
        <br>
        <br>
        Tom
        <br>
      </blockquote>
      <br>
    </blockquote>
    <br>
    <pre class="moz-signature" cols="72">-- 
Martin Lunze
IT-Systemadministrator

Technische Universität Dresden
Zentrum für Informationsdienste und Hochleistungsrechnen (ZIH)
Operative Prozesse und Systeme (OPS)
01062 Dresden

Tel.: +49 (351) 463-35881
E-Mail: <a class="moz-txt-link-abbreviated" href="mailto:martin.lunze@tu-dresden.de">martin.lunze@tu-dresden.de</a></pre>
  </body>
</html>