<html xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=Windows-1252">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0cm;
font-size:10.0pt;
font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:blue;
text-decoration:underline;}
span.EmailStyle19
{mso-style-type:personal-reply;
font-family:"Calibri",sans-serif;
color:windowtext;}
.MsoChpDefault
{mso-style-type:export-only;
font-size:10.0pt;}
@page WordSection1
{size:612.0pt 792.0pt;
margin:72.0pt 72.0pt 72.0pt 72.0pt;}
div.WordSection1
{page:WordSection1;}
--></style>
</head>
<body lang="en-VN" link="blue" vlink="purple" style="word-wrap:break-word">
<div class="WordSection1">
<p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
<div style="border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0cm 0cm 0cm">
<p class="MsoNormal" style="mso-margin-top-alt:0cm;margin-right:0cm;margin-bottom:12.0pt;margin-left:36.0pt">
<b><span style="font-size:12.0pt;color:black">From: </span></b><span style="font-size:12.0pt;color:black">users <users-bounces@shibboleth.net> on behalf of Peter Schober <peter.schober@univie.ac.at><br>
<b>Date: </b>Monday, 6 December 2021 at 17:45<br>
<b>To: </b>users@shibboleth.net <users@shibboleth.net><br>
<b>Subject: </b>Re: Shibboleth.DEPRECATION : MetadataGenerator handler<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:36.0pt"><span style="font-size:11.0pt">* Jan Vilhuber <JVilhuber@absolute.com> [2021-12-06 05:48]:<br>
> I can’t find anything about this in the Release-notes or google. Can<br>
> someone give details? Is it being replaced with something else? If I<br>
> missed some obvious place, I apologize for the noise!<br>
<br>
I'm guessing the thing you've missed are countless discussions on this<br>
list about how serving up metadata for others using that endpoint is<br>
insecure (self-asserted, never expiring, unsigned metadata provides<br>
zero trust but is still often directly/dynamically used to establish<br>
key material that's then relied upon for securing SAML protocol<br>
messages) and how the internal config sometimes needs to differ from<br>
the external view during changes, e.g. what keys are internally<br>
configured/available vs. which ones are included in published metadata<br>
and with what use-limitations, if any.<br>
<br>
<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US" style="font-size:11.0pt">No, I didn’t miss those discussions and I did read the warnings in the wiki. I was under the (apparently mistaken) impression the endpoint could still be used for internal purposes, though.<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US" style="font-size:11.0pt"><o:p> </o:p></span></p>
<p class="MsoNormal"><span lang="EN-US" style="font-size:11.0pt">Thanks. I’ll have a look at metagen.sh.<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US" style="font-size:11.0pt">Jan<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US" style="font-size:11.0pt"><o:p> </o:p></span></p>
<p class="MsoNormal" style="margin-left:36.0pt"><span style="font-size:11.0pt"><br>
The replacement has been the metagen.sh script and further curating<br>
that metadata yourself as needed, I'd expect.<br>
<br>
As a federation operator I do find the metadata generator endpoint<br>
very useful as it helps with blackbox debugging, e.g. discovering<br>
supported (or changed) EncryptionMethod values which the SP software<br>
dynamically generates but I realise that's not the common case.<br>
<br>
I also note that e.g. SimpleSAMLphp doesn't seem to have such concerns<br>
about internal configration vs. published metadata as part of key<br>
rollover, cf. <a href="https://urldefense.com/v3/__https:/simplesamlphp.org/docs/stable/saml:keyrollover__;!!GEjU_1jlQXGQfQ!0DJ0ZSokGAzmq2oq3vdlSnzQYdTw-XoGhbtXfDcL79bUyFEJFWqpM84uFSMzhh6Umw$">
https://urldefense.com/v3/__https://simplesamlphp.org/docs/stable/saml:keyrollover__;!!GEjU_1jlQXGQfQ!0DJ0ZSokGAzmq2oq3vdlSnzQYdTw-XoGhbtXfDcL79bUyFEJFWqpM84uFSMzhh6Umw$</a>
<br>
(AFAICT the Shib SP offers simmilar features here so I'm probably<br>
missing something more fundamental here.)<br>
<br>
-peter<br>
-- <br>
For Consortium Member technical support, see <a href="https://urldefense.com/v3/__https:/shibboleth.atlassian.net/wiki/x/ZYEpPw__;!!GEjU_1jlQXGQfQ!0DJ0ZSokGAzmq2oq3vdlSnzQYdTw-XoGhbtXfDcL79bUyFEJFWqpM84uFSNi2FAfEw$">
https://urldefense.com/v3/__https://shibboleth.atlassian.net/wiki/x/ZYEpPw__;!!GEjU_1jlQXGQfQ!0DJ0ZSokGAzmq2oq3vdlSnzQYdTw-XoGhbtXfDcL79bUyFEJFWqpM84uFSNi2FAfEw$</a>
<br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<o:p></o:p></span></p>
</div>
</div>
</body>
</html>