Skip to Content.
Sympa Menu

shibboleth-dev - Re: Encryption key strategies

Subject: Shibboleth Developers

List archive

Re: Encryption key strategies


Chronological Thread 
  • From: Ian Young <>
  • To:
  • Subject: Re: Encryption key strategies
  • Date: Wed, 28 Jun 2006 10:47:18 +0100

Reimer Karlsen-Masur, DFN-CERT wrote:

(Or put the stuff into the meta data. But that does not scale.)

I'm not sure that adding more elements to the metadata for individual entities changes the scalability much (it's "just" a constant factor).

I think the real scalability issue is that we are relying on a monolithic representation of metadata as a single document at the federation level (with, I have to assume, corresponding in-memory representations).

Current federations haven't hit sizes where that's a real challenge, but obviously the situation won't get any better from here. In the long run, we'll need to move away from a monolithic representation in the same way as the Internet moved away from a monolithic HOSTS file. If entities only need to parse and cache the metadata for other entities they are in active communication with, the size of the individual entity metadata documents becomes much less important.

-- Ian



Archive powered by MHonArc 2.6.16.

Top of Page