<div dir="ltr">Sounds good, thanks Scott.<div><br></div><div>Mike.</div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Wed, Feb 5, 2020 at 5:10 PM Cantor, Scott <<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">You will never see a (correct) instance of metadata or any other ds:X509Certificate element anywhere with the headers. The relevant standard is XML Signature, and the syntax of that element is a base64-encoded DER-encoded certificate. PEM is simply that format with the headers added. The XML Schema type of the element is called base64Binary. The headers are not valid base64 so they blatantly break the syntax and would choke any validating parser.<br>
<br>
> I noticed the metadata/idp-metadata.xml configuration file references<br>
<br>
There is no such configuration file. The IdP never uses its own metadata. That file is a dummy example file (really should never have been created, but it's historical) that's just a sample. It should never be used as anything but a starting point for creating the appropriate metadata to give to federations and the like.<br>
<br>
> I've seen ADFS SAML 2.0 references contain the certificate headers and footers<br>
<br>
I would be surprised, but given that ADFS can't even handle valid metadata, it would be fitting if it accepted something that's clearly invalid.<br>
<br>
> and I didn't see the OASIS SAML 2.0 specify whether the headers and footers were needed<br>
<br>
Because it's not a SAML element. It comes from XML Signature.<br>
<br>
-- Scott<br>
<br>
<br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div><br clear="all"><div><br></div>-- <br><div dir="ltr" class="gmail_signature"><div dir="ltr"><div><div dir="ltr">Respectfully,<div><br></div><div>Mike Lloyd</div><div>Innovation Specialist, 18F, <a href="http://cloud.gov" target="_blank">cloud.gov</a></div><div>g: mxplusb</div></div></div></div></div>