shibboleth-dev - Re: Comments on the new configuration
Subject: Shibboleth Developers
List archive
- From: Tom Scavo <>
- To: Howard Gilbert <>
- Cc:
- Subject: Re: Comments on the new configuration
- Date: Tue, 24 May 2005 09:28:38 -0400
- Domainkey-signature: a=rsa-sha1; q=dns; c=nofws; s=beta; d=gmail.com; h=received:message-id:date:from:reply-to:to:subject:cc:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references; b=pPYxLjYz/iTCnWjuEkTZ+g6NvkbitqO/m+pkDQLRNwckfB8sVHyzcBBP9e/i3MTCLD/0DislU8LyRxQ+/sxV9XSwiSTykdRwWuoFeb2kRMEZFgMqCGdqYgNugYVzRziug8Yo/kT57MqbGN/e/unxCOm0GIiUcQinlvRyXhU2cYo=
On 5/24/05, Howard Gilbert
<>
wrote:
> > Because as you said, the IdP and SP share metadata with each other, so
> > why wouldn't the IdP's metadata be in one file and the SP's metadata
> > be in another. It reinforces the idea that metadata files are swapped
> > and that an entity need not consume its own metadata.
>
> In the long run, I would argue the exact opposite. Metadata is global and
> should be shared by everyone, including the Entity that it describes.
In what sense does an entity share its metadata with itself?
> However, at some point we should add sanity checks so that an entity
> consumes its own Metadata and compares it to the configuration file. An
> alarm should go off if, for example, the Private Key in Credentials cannot
> be validated against your own Certificates in the Metadata, or if an
> AttributeConsumer URL in the SP configuration isn't found in its Metadata.
Ah, I see. Those are certainly good ideas but all the metadata need
not be in a single file for this to happen.
> However, such a sanity check is not required for correct operation, and
> right now we have more pressing matters on the queue. Just because we don't
> use it yet doesn't mean we should go out of our way to exclude it.
Putting metadata into separate files doesn't preclude any of your
useful sanity checks.
Thanks,
Tom
- Comments on the new configuration, Howard Gilbert, 05/23/2005
- Re: Comments on the new configuration, Scott Cantor, 05/23/2005
- RE: Comments on the new configuration, Howard Gilbert, 05/23/2005
- RE: Comments on the new configuration, Scott Cantor, 05/23/2005
- RE: Comments on the new configuration, Howard Gilbert, 05/23/2005
- Re: Comments on the new configuration, Tom Scavo, 05/23/2005
- Re: Comments on the new configuration, Scott Cantor, 05/23/2005
- Re: Comments on the new configuration, Tom Scavo, 05/23/2005
- RE: Comments on the new configuration, Scott Cantor, 05/23/2005
- RE: Comments on the new configuration, Howard Gilbert, 05/24/2005
- Re: Comments on the new configuration, Tom Scavo, 05/24/2005
- Re: Comments on the new configuration, Tom Scavo, 05/23/2005
- Re: Comments on the new configuration, Scott Cantor, 05/23/2005
- Re: Comments on the new configuration, Scott Cantor, 05/23/2005
Archive powered by MHonArc 2.6.16.