Skip to Content.
Sympa Menu

per-entity - Re: [Per-Entity] remaining BIG questions

Subject: Per-Entity Metadata Working Group

List archive

Re: [Per-Entity] remaining BIG questions


Chronological Thread 
  • From: "Cantor, Scott" <>
  • To: Tom Scavo <>
  • Cc: Nick Roy <>, Per-Entity Metadata Working Group <>
  • Subject: Re: [Per-Entity] remaining BIG questions
  • Date: Wed, 14 Sep 2016 19:47:13 +0000
  • Accept-language: en-US
  • Authentication-results: spf=pass (sender IP is 164.107.81.210) smtp.mailfrom=osu.edu; incommon.org; dkim=none (message not signed) header.d=none;incommon.org; dmarc=bestguesspass action=none header.from=osu.edu;
  • Ironport-phdr: 9a23:q/iIhxQvXP5pCG7lMOA/GfJO4Npsv+yvbD5Q0YIujvd0So/mwa67bRKN2/xhgRfzUJnB7Loc0qyN7PCmBDdLuMvJmUtBWaIPfidNsd8RkQ0kDZzNImzAB9muURYHGt9fXkRu5XCxPBsdMs//Y1rPvi/6tmZKSV3XfDB4LeXtG4PUk9//l6Xro8WSME10g2+BZrY6Fx6/swKZ4tUMmoBrNKEZyx3Vr2FOdvgMg25kOATAsQz745L615dl7yNK/7oa/MlcTe+yK68xS6BfFnJ8G2cu+YvmuQSVHljH3WcVTmhDykkAOAPC9hyvG86p6iY=
  • Spamdiagnosticmetadata: NSPM
  • Spamdiagnosticoutput: 1:99

On 9/14/16, 3:05 PM,
"
on behalf of Tom Scavo"
<
on behalf of
>
wrote:

> This is what I was trying to say on the call: We need to implement
> on-demand metadata signing, which is the ability for authorized
> personnel to initiate a metadata signing operation from anywhere at
> any time. We have a plan for that but no time frame.

Understood.

> Today we deal with that in documentation: "It is strongly recommended
> that InCommon SPs and IdPs refresh and verify metadata at least daily.
> An optimal configuration would attempt to refresh metadata every hour
> (assuming your client supports HTTP Conditional GET)."

In both the batch and MDQ cases, our metadata code will allow cacheDuration
to influence the behavior, so if you want people to refresh every hour, you
can set cacheDuration to cause that to happen, within some boundaries the
deployer can set. You don't have to just rely on advice.

-- Scott





Archive powered by MHonArc 2.6.19.

Top of Page