<div dir="ltr"><div dir="ltr">Thanks Nate and Kevin for your input<div><br></div><div>Peter,  thanks for your input also.  I appreciate your recommendation not to do something I shouldn't ...especially when stated so nicely!  :-)    I have no specific intention at the moment.  I was just wanting to reference some information in the metadata and with the idp 2.x I just popped it up in my browser when needed.   sometimes it's easier to do that if I don't already have an ssh session open to the box .... displays well too.   I was frustrated because I know I knew the url previously  ...ugh wasted 40 mins trying to find it and left late for my commute home.   I hate ending my day like that.  </div><div><br></div><div>Thanks Everyone.<br clear="all"><div><div dir="ltr" class="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div><div></div><div><br></div><div>Brad Mathis</div><div>IT Systems Architect </div><div>Infrastructure Services - Applications<br></div><div>Pima Community College<br></div><div>520.206.4826<br></div><div><a href="mailto:bmathis@pima.edu" target="_blank">bmathis@pima.edu</a></div></div><div><br></div><div><img src="https://docs.google.com/uc?export=download&id=1-cXzKNARwUoDuBUcqPuKHQtqN6T9Kc-K&revid=0B4QEFWYNTFJAZkhsVXhoUi8rWE1NbURBWEorZjVRNFc5ZE9JPQ" width="200" height="147"><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div><br></div></div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Tue, Mar 10, 2020 at 6:52 PM Peter Schober <<a href="mailto:peter.schober@univie.ac.at">peter.schober@univie.ac.at</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">* Mathis, Bradley <<a href="mailto:bmathis@pima.edu" target="_blank">bmathis@pima.edu</a>> [2020-03-11 00:42]:<br>
> In idp 2.x   <a href="https://myIdp.domain/idp/profile/Metadata/SAML" rel="noreferrer" target="_blank">https://myIdp.domain/idp/profile/Metadata/SAML</a>  would show me<br>
> the metadata for my idp.<br>
> <br>
> What's the equivalent for idp 3.x?<br>
<br>
Since the How was sufficiently answered I'll risk asking Why:<br>
<br>
Why would you want to load your own metadata -- that's very likely to<br>
be unsigned and either already expired or will never expire or much<br>
too far in the future -- over the network?<br>
<br>
I'm geussing you're probably not interested in your own metadata<br>
yourself (as you could find that on disk in metadata/idp-metadata.xml)<br>
but thinking about pointing Service Providers to that URL for trust<br>
(cough!) establishment?  If so that's a clear anti-pattern and<br>
alternatives should be considered (such as those SPs loading your IDP<br>
metadata from the InCommon MDQ service, verifying the signature of<br>
that metadata every time with InCommon's published metadata signing<br>
certificate.)<br>
<br>
So if you could add something about the Why I'm sure we can add<br>
something about the Why Not. ;)<br>
<br>
-peter<br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>