Skip to Content.
Sympa Menu

metadata-support - RE: [Metadata-Support] The per-entity metadata pilot and the requireSignedMetadata attribute

Subject: InCommon metadata support

List archive

RE: [Metadata-Support] The per-entity metadata pilot and the requireSignedMetadata attribute


Chronological Thread 
  • From: "Wessel, Keith" <>
  • To: "" <>
  • Subject: RE: [Metadata-Support] The per-entity metadata pilot and the requireSignedMetadata attribute
  • Date: Tue, 6 Sep 2016 21:27:40 +0000
  • Accept-language: en-US
  • Ironport-phdr: 9a23:4MIBYhT3ZCRY26en+Zk/mynZWtpsv+yvbD5Q0YIujvd0So/mwa64ZByN2/xhgRfzUJnB7Loc0qyN7PCmBDdLuMvJmUtBWaIPfidNsd8RkQ0kDZzNImzAB9muURYHGt9fXkRu5XCxPBsdMs//Y1rPvi/6tmZKSV2sfTZyc67wF5Lbg82r3qWp5oXLZB9UrDu7arR3KRKw6wLLuYNe1Y5vNq89wwfA52BVY/xR339AJFSYmBP54cH2+4RspXd+ofUkooR/XL7hcqB8BZ9VDSgmeShh59LmrgLOSSOO4n8dVGIXiVxFDxWTv0KyZYv4riav7rk14yKdJ8CjFb0=

Thanks, Tom. Good to know that I'm living on the edge. :) As I think I
discussed previously on one list or another, there's not a lot one can do
with MDQ testing as an IDP operator at this point except for locally by
changing my /etc/hosts to redirect IDP traffic to my test IDP cluster. But
that's better than nothing.

Keith


-----Original Message-----
From:


[mailto:]
On Behalf Of Tom Scavo
Sent: Tuesday, September 06, 2016 3:06 PM
To:

Subject: Re: [Metadata-Support] The per-entity metadata pilot and the
requireSignedMetadata attribute

Hi Keith,

On Tue, Sep 6, 2016 at 2:59 PM, Wessel, Keith
<>
wrote:
>
> I have my test IDP cluster querying metadata from the InCommon MDQ server.

Note that mdq-beta.incommon.org imports metadata from the InCommon
preview aggregate so that's a fine use of this beta MDQ server.

> I configured the IDP using the instructions on
> https://spaces.internet2.edu/display/InCCollaborate/Dynamic+Metadata+Client+Config#DynamicMetadataClientConfig-ShibbolethIdPConfiguration.

AFAIK, you are the first one to test that configuration, Keith. Thank
you for venturing to the leading edge :-)

> However, my IDP has reminded me evern since I did this that the
> requireSignedMetadata attribute of the signature validation filter is
> deprecated.

Oops, apparently I overlooked that.

> Is it syntactically correct to use the new requireSignedRoot attribute in
> this configuration instead?

Yes, I think so (but I don't know if it's ever been tried).

> I'm not sure if metadata coming back from the MDQ server has a signed root.

The root element is <md:EntityDescriptor> and yes, it is signed.

> I would expect it would but wanted to know for sure. If so, it might be
> good to update that wiki page.

I will do that, thanks. Be sure to let us know if you discover anything else.

Thanks Keith.

Tom



Archive powered by MHonArc 2.6.19.

Top of Page