<!DOCTYPE html>
<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
  </head>
  <body>
    <p>Hi list,</p>
    <p>FWIW, we've just done a 5.2.2 test upgrade and the DFN-AAI
      re-published eduGAIN SP metadata feed loads without issues.
      Apparently the IdP is able to use it, i.e. react upon a persistent
      NameID declaration in metadata using AACLI. </p>
    <p>Mayby the issue is OS-dependent? This customer's IdP is on
      Ubuntu24 with a distribution's tomcat10 and OpenJDK21. We'd even
      enforced "<span style="white-space: pre-wrap">idp.xml.elementAttributeLimit = 30" but it works still.</span></p>
    <p>Regards</p>
    <p>Martin</p>
    <div class="moz-cite-prefix">Am 14.05.26 um 18:23 schrieb Bernd
      Oberknapp:<br>
    </div>
    <blockquote type="cite"
      cite="mid:cf15f6ec-9650-4707-a489-aa149d8cc21e@ub.uni-freiburg.de">
      <br>
      On 5/14/26 17:20, Peter Schober via users wrote:
      <br>
      <blockquote type="cite">
        <br>
        <blockquote type="cite">That leads directly to the point that
          it's not meant for public
          <br>
          consumption, it's a system artifact of a service designed to
          be used
          <br>
          by the federations. If they're happy with it, fine. But by
          exposing
          <br>
          it to clients, I think they kind of have an obligation to do
          things
          <br>
          sensibly or tell people that they don't intend to cater to
          that use
          <br>
          case.
          <br>
        </blockquote>
        <br>
        I think there probably were (are?) a few offenders among the
        eduGAIN
        <br>
        participant federations who did not understand that it's plain
        wrong
        <br>
        to point their members to the eduGAIN MDS ("trust is always
        local", as
        <br>
        leifj often said, here meaning: there's no reason any IDP or SP
        <br>
        deployer should trust the eduGAIN MDS metadata or signing key).
        <br>
        If this were up to me I'd long have restricted access to that
        resource
        <br>
        to only the participant federations who need to process it.
        <br>
        Doing that now doesn't of course address the issue.
        <br>
      </blockquote>
      <br>
      Just to clarify, our IdP uses the eduGAIN SP metadata file
      provided by the DFN-AAI (not the one provided by eduGAIN), but
      that has the same issue.
      <br>
      <br>
      Best regards,
      <br>
      Bernd
      <br>
      <br>
      <br>
      <fieldset class="moz-mime-attachment-header"></fieldset>
    </blockquote>
    <div class="moz-signature">-- <br>
      <p><strong>Dr. MARTIN HITSCHEL | System Engineer</strong></p>
      <p>Phone: +49 7071 407109-0<br>
        Email: <a>martin.hitschel@daasi.de</a></p>
      <p><strong>DAASI International GmbH</strong><br>
        Europaplatz 3<br>
        D-72072 Tübingen, Germany<br>
        <a class="moz-txt-link-abbreviated" href="http://www.daasi.de">www.daasi.de</a></p>
      <p>Registered Office: Tübingen<br>
        Registration Court: Amtsgericht Stuttgart, HRB 382175<br>
        CEO: Peter Gietz</p>
    </div>
  </body>
</html>