Skip to Content.
Sympa Menu

shibboleth-dev - Re: [Shib-Dev] Metadata verification before overwriting local copy

Subject: Shibboleth Developers

List archive

Re: [Shib-Dev] Metadata verification before overwriting local copy


Chronological Thread 
  • From: Chad La Joie <>
  • To:
  • Subject: Re: [Shib-Dev] Metadata verification before overwriting local copy
  • Date: Thu, 25 Feb 2010 11:31:46 -0500
  • Organization: Itumi, LLC

I don't *think* this would on the IdP. I think the IdP waits to write out the backup file until after it has successfully parsed and validated the incoming file.

On 2/25/10 11:28 AM, André Cruz wrote:
Hello.

I recently ran into a problem with the federation metadata and I think it
could be better handled by the Shibboleth software. I tested this on an SP
2.2.1 but it's possible it applies to the IDP as well.

What happened was that the server that hosts my metadata had a problem, and
started serving a default page, in xhtml. The SP fetched this, as it was
valid xml trashed the local file, and failed to load the new file keeping the
valid metadata in memory. If a restart happens before the SP can fetch a
valid metadata again, it will fail.

I know these were very specific circumstances but can't the SP and IDP make
sure the metadata fetched is valid before overwriting the local file? Should
I file it in JIRA?

Best regards,
André Cruz



--
Chad La Joie
www.itumi.biz
trusted identities, delivered



Archive powered by MHonArc 2.6.16.

Top of Page