Skip to Content.
Sympa Menu

per-entity - Re: [Per-Entity] implementing a cache on the client

Subject: Per-Entity Metadata Working Group

List archive

Re: [Per-Entity] implementing a cache on the client


Chronological Thread 
  • From: Nick Roy <>
  • To: Jorj Bauer <>, "" <>
  • Subject: Re: [Per-Entity] implementing a cache on the client
  • Date: Wed, 27 Jul 2016 21:29:20 +0000
  • Accept-language: en-US
  • Authentication-results: spf=none (sender IP is ) ;
  • Spamdiagnosticmetadata: NSPM
  • Spamdiagnosticoutput: 1:99

Why not? The caching proxy takes the request and retrieves the target
document, then the SAML deployment trusts the presumably self-signed cert on
the caching proxy. In any case, this is one reason it's great that our trust
model doesn't depend on browser TLS.

Nick

On 7/27/16, 3:04 PM,
"
on behalf of Jorj Bauer"
<
on behalf of
>
wrote:

>> That said, if others want to run their own local copy, why don't they
just stand up local
>> HTTP proxies?
>
> Caching proxies, at least. Obviously they can, but I was reacting to
the idea that we could somehow rely on that being common as a stopgap for the
primary being reliable enough. It was never the intent that the Shibboleth
implementation would demand that backstop.

... until you migrate to https, and then you can't cache the
intermediate document.






Archive powered by MHonArc 2.6.19.

Top of Page