<html><body><div style="font-family: arial, helvetica, sans-serif; font-size: 12pt; color: #000000"><div style="font-family: arial, helvetica, sans-serif; font-size: 12pt; color: #000000">Thanks Ian,<div>setting <em>p:descriptorName="myname"</em> in <em>EntitiesDescriptorAssemblerStage</em> bean does the job :</div><div><em><bean id="createEntitiesDescriptor" class="net.shibboleth.metadata.dom.saml.EntitiesDescriptorAssemblerStage"<strong> p:descriptorName="IMT-FR-Fed"</strong> ></em></div><div><br></div><div>result in the header of my aggregated metadatas:</div><div><em><md:EntitiesDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" ID="_5d12a60c-35a9-4120-8f28-8a4b20173ce5" <strong>Name="IMT-FR-Fed"</strong>><Signature xmlns="http://www.w3.org/2000/09/xmldsig#"><SignedInfo></em></div><div><br></div><div id="f254a2c9-db33-4a7f-b6f0-7316e8aa3815" data-marker="__SIG_PRE__"><div>by the way, I realize that this version of aggregator-cli-0.9.2 does the signature of my aggregated metadatas (thanks to pipeline stage : <ref bean="signMetadata"/> ) <br></div><div>in 0.7 I used to sign it with xmlsectool :</div><div><pre>./xmlsectool.sh --sign --inFile fede-unsigned.xml --outFile fede-signed.xml --certificate ../ssl/fede-cert.pem --key ../ssl/fede-key.pem </pre></div><div>do you confirm that this external xmlsectool signature is a duplicate and bean="signMetadata" does the same job ?</div><div><br></div><div>Regarding your suggestion about relying on the EntitiesDescriptor/@Name , I don't use MDQ-style yet , but I'll keep an eye on it .<br></div><div><br></div><div>As you suggested , I did opened a JIRA ticket do add examples : <a href="https://issues.shibboleth.net/jira/browse/MDA-261" data-mce-href="https://issues.shibboleth.net/jira/browse/MDA-261">https://issues.shibboleth.net/jira/browse/MDA-261</a><br data-mce-bogus="1"></div><div><br></div><div>Thanks</div><div><br>Jehan</div></div><br><hr id="zwchr" data-marker="__DIVIDER__"><div data-marker="__HEADERS__"><b>De: </b>"Ian Young" <ian@iay.org.uk><br><b>À: </b>"Jehan PROCACCIA" <jehan.procaccia@tem-tsp.eu><br><b>Cc: </b>"users" <users@shibboleth.net><br><b>Envoyé: </b>Vendredi 9 Juillet 2021 17:16:11<br><b>Objet: </b>Re: Matadata aggregator , federation named groupID for filters<br></div><br><div data-marker="__QUOTED_TEXT__"><br class=""><div><br class=""><blockquote class=""><div class="">On 2021-07-09, at 13:13, Jehan PROCACCIA <<a href="mailto:jehan.procaccia@tem-tsp.eu" class="" target="_blank">jehan.procaccia@tem-tsp.eu</a>> wrote:</div><br class="Apple-interchange-newline"><div class=""><div class=""><div style="font-family: arial, helvetica, sans-serif; font-size: 12pt;" class=""><div id="zimbraEditorContainer" style="font-family: arial, helvetica, sans-serif; font-size: 12pt;" class="32"><div class=""><span style="font-size: 12pt;" class="">Ian.Y told me to use </span><em class="" style="font-size: 12pt;">descriptorName property</em><span style="font-size: 12pt;" class=""> , but I cannot find this feature documented on </span><a href="https://wiki.shibboleth.net/confluence/display/MA1/Aggregate+and+Sign" class="" style="font-size: 12pt;" target="_blank">https://wiki.shibboleth.net/confluence/display/MA1/Aggregate+and+Sign</a><br data-mce-bogus="1"></div></div></div></div></div></blockquote><div><br class=""></div><div><br class=""></div><div>Detailed documentation of the individual beans is in the Javadoc. In this case, you want this:</div><div><br class=""></div><div><a href="https://shibboleth.net/sites/release/java-metadata-aggregator/0.9.2/apidocs/net/shibboleth/metadata/dom/saml/EntitiesDescriptorAssemblerStage.html" class="" target="_blank">https://shibboleth.net/sites/release/java-metadata-aggregator/0.9.2/apidocs/net/shibboleth/metadata/dom/saml/EntitiesDescriptorAssemblerStage.html</a><br data-mce-bogus="1"></div><div><br class=""></div><div>So if you are building your aggregate using the EntitiesDescriptorAssemblerStage, you can set the descriptorName property by, for example, including p:descriptorName="myname" in its definition.</div><div><br class=""></div><div>(The documentation in Confluence currently links to the 0.10.0-SNAPSHOT Javadoc, but it's fairly similar. That might need to change.)</div></div><div class=""><br class="webkit-block-placeholder"></div><div class="">There's a case to be made that we could use a lot more HOWTO examples. At the moment, a lot of the detailed stuff the MDA provides is only visible in the Javadoc, and not everyone will know how to work with that. Can you make a JIRA ticket to suggest we add an example that names an aggregate?[1] </div><div class="">
<span class="Apple-style-span" style="border-collapse: separate; color: rgb(0, 0, 0); font-family: Helvetica; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; border-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-stroke-width: 0px;"><div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class=""><span class="Apple-style-span" style="border-collapse: separate; color: rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; border-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-stroke-width: 0px;"><div class=""><span class="Apple-tab-span" style="white-space: pre;"><br class="Apple-interchange-newline"></span> -- Ian<br class=""></div><div class=""><span class="Apple-style-span" style="font-size: medium;"><br class=""></span></div></span></div></span><br class="Apple-interchange-newline">[1] Note that, as I said before, I wouldn't really recommend relying on the EntitiesDescriptor/@Name, it doesn't scale very well.</div>
<br class=""></div></div><div><br></div></div></body></html>