Skip to Content.
Sympa Menu

per-entity - Re: [Per-Entity] supporting metadata distribution via HTTPS

Subject: Per-Entity Metadata Working Group

List archive

Re: [Per-Entity] supporting metadata distribution via HTTPS


Chronological Thread 
  • From: "Cantor, Scott" <>
  • To: Paul Caskey <>, Thomas Scavo <>, Per-Entity Metadata Working Group <>
  • Subject: Re: [Per-Entity] supporting metadata distribution via HTTPS
  • Date: Wed, 7 Sep 2016 16:54:57 +0000
  • Accept-language: en-US
  • Authentication-results: spf=pass (sender IP is 164.107.81.210) smtp.mailfrom=osu.edu; incommon.org; dkim=none (message not signed) header.d=none;incommon.org; dmarc=bestguesspass action=none header.from=osu.edu;
  • Ironport-phdr: 9a23:Ld7MeBBG3MPpka5ZDHnhUyQJP3N1i/DPJgcQr6AfoPdwSP7yoMbcNUDSrc9gkEXOFd2Crakb26yL6Ou5BCQp2tWojjMrSNR0TRgLiMEbzUQLIfWuLgnFFsPsdDEwB89YVVVorDmROElRH9viNRWJ+iXhpRZbIBj0NBJ0K+LpAcaSyp3vj6Hhs6HUNj1BmT71SrppLxin5VHJvcANgoZzAqc31hbTpHZUIaJbyX4+YRqvnxH579z4x5Vq7SMY7+477MVJT6LSfqIkQKZeASh8dW05+Zuv/SHOV06i4GcdTnRetxdUCgTM8BiyYZDrsSr8uaJSwi6HJYWiVb0uHDmk86Z3WTfpjiwAMjs+9ifQkMMm34xBpxf07Td2xZLTesXdD/F5Yr+XNYcRTGxdWdwXDQRGGZ76YocSWblSdd1EppXw8gNd5SC1AhOhUaa2kmdF
  • Spamdiagnosticmetadata: NSPM
  • Spamdiagnosticoutput: 1:99

On 9/7/16, 12:30 PM,
"
on behalf of Paul Caskey"
<
on behalf of
>
wrote:

> The way I heard our discussion earlier was that http would be the
> primary (and
> documented) path, same as always.

I don't have a strong feeling about what gets documented, but I personally
would use https and that might cause problems if I'm public with that
preference.

I understand the concern with confusion, but I also think we are worried
about the people who shouldn't be running IdPs at the expense of the people
who can. Using TLS with *some* legitimate trust anchor is better for
security, pretty much a priori, so we'd be deliberately weakening things for
everybody else. That's before considering that this is simply necessary to
make ADFS a participant in this mix.

> It’s ironic that the introduction of TLS might actually degrade the
overall trust
> fabric of the federation, but that is my fear.

I think the fear is already reflected by current practice. We get enough
questions and posted configurations to my list to tell me that plenty of
people are blindly pulling metadata over http now without verifying it. I
really don't think you can make people behave any worse than they do now.

But I think most people cut and paste. I don't think they're going to go out
of their way to do something that doesn't match an explicit example.

-- Scott





Archive powered by MHonArc 2.6.19.

Top of Page