Skip to Content.
Sympa Menu

per-entity - Re: [Per-Entity] distribution of aggregate metadata

Subject: Per-Entity Metadata Working Group

List archive

Re: [Per-Entity] distribution of aggregate metadata


Chronological Thread 
  • From: Nick Roy <>
  • To: "Cantor, Scott" <>
  • Cc: Chris Phillips <>, "Per-Entity Metadata Working Group" <>
  • Subject: Re: [Per-Entity] distribution of aggregate metadata
  • Date: Thu, 11 Aug 2016 17:49:08 +0000
  • Accept-language: en-US
  • Authentication-results: spf=none (sender IP is ) ;
  • Ironport-phdr: 9a23:rJCZuRPQRhN3aLqbHYcl6mtUPXoX/o7sNwtQ0KIMzox0K/X5rarrMEGX3/hxlliBBdydsK0UzbeN+Pm9EUU7or+/81k6OKRWUBEEjchE1ycBO+WiTXPBEfjxciYhF95DXlI2t1uyMExSBdqsLwaK+i76xXcoFx7+LQt4IPjuUs6X1pzvlrP6x5qGKS5Bgia6e/c6Fx6xsRmb/p0diI1+Lbx3kDPOuWYOduhLkzBGP1WWyjD97cT4xplyu3BWofUw389GTajgeakkF/pVAClwYDN939HiqRSWFVjH3XAbSGhD10MQWwU=
  • Spamdiagnosticmetadata: NSPM
  • Spamdiagnosticoutput: 1:99


Nick Roy
Director of Technology and Strategy, InCommon
Internet2, Denver (GMT -6:00)

On Aug 11, 2016, at 11:15 AM, Cantor, Scott <> wrote:

The documentation says that the checks happen every 2-4 minutes.  That’s
not good enough for what Scott is asking, it seems.

Certainly depends on which 2 minutes you happen to be logging in to an SP for the first time might be, and that applies even with caching.

I understand there's no way to be perfect, but this really can't fail any more often than DNS onsite does today, and as others have noted, the difference here is that it's a system outside your network essentially hosting your sole DNS option. If we can't reach a comfort level with that, it's entirely possible we have to step back to first principles.

It's obviously true that a local layer changes this a lot, and I'm sure starting to talk myself into one, but it remains true that that's not a solution for the majority.

The "win" with endpoint-hosted is that the site that's down *is* the site that's down, obviously.

Endpoint-hosted metadata that is signed by a federation operator starts to look a lot like a SAML version of what Roland’s proposing with OpenID Connect.

Nick

-- Scott






Archive powered by MHonArc 2.6.19.

Top of Page