per-entity - Re: [Per-Entity] adding a layer to the security model
Subject: Per-Entity Metadata Working Group
List archive
- From: Tom Scavo <>
- To: "Cantor, Scott" <>
- Cc: Tom Scavo <>, Per-Entity Metadata Working Group <>
- Subject: Re: [Per-Entity] adding a layer to the security model
- Date: Wed, 21 Sep 2016 13:06:02 -0400
- Ironport-phdr: 9a23:yYbC4BCPQJEvalHhP6jJUyQJP3N1i/DPJgcQr6AfoPdwSP3yocbcNUDSrc9gkEXOFd2Crakb26yL6Ou5BCQp2tWojjMrSNR0TRgLiMEbzUQLIfWuLgnFFsPsdDEwB89YVVVorDmROElRH9viNRWJ+iXhpRZbIBj0NBJ0K+LpAcaSyp3vj6Hhs6HUNk9jjTyhZqk2ZC69qhnN/IFCioJkNqErjEHhpWBVPela2DU7C0iUmkPA4cL4x5Vq7SMY7+477MVJT6LSfqIkQKZeASh8dW05+Zu45lH4UQKT6y5EAS0tmR1SDl2AtUmiUw==
On Wed, Sep 21, 2016 at 12:15 PM, Cantor, Scott
<>
wrote:
> On 9/21/16, 12:09 PM,
> "
> on behalf of Tom Scavo"
> <
> on behalf of
> >
> wrote:
>
>> Can you describe how content-negotiation might play into this?
>
> I just mean the files would be pre-signed in various formats and pushed
> out, and then the server would look at the Accept header to decide which
> format to return. Maybe with MIME type options or just by defining custom
> MIME types or whatever.
Ah, so I *did* misunderstand you. I think you're suggesting we publish
JSON format metadata in addition to XML. I don't disagree with that.
It overlaps with conversations we've had regarding JSON feeds for
discovery.
> I suppose if the formats composite safely maybe it doesn't matter that
> much, but there's certainly a non-trivial parsing overhead to XML Signature
> since all that XML is rather bloated.
Yes, many developers and deployers dismiss XML out of hand (whether or
not it's warranted).
> This is OT: I suppose we haven't discussed this, but it isn't essential
> that the KeyInfo be included here. It's good practice I guess, but when
> you're signing ton of little files, it seems more gratuitious to me to
> include a reference to the key everybody already needs to have installed.
> It's meaningless in a huge file, but in these? I'm thinking not so much.
Okay, I'll add this tidbit to:
https://issues.shibboleth.net/jira/browse/MDA-76
Thanks,
Tom
- [Per-Entity] adding a layer to the security model, Tom Scavo, 09/21/2016
- Re: [Per-Entity] adding a layer to the security model, Cantor, Scott, 09/21/2016
- Re: [Per-Entity] adding a layer to the security model, Tom Scavo, 09/21/2016
- Re: [Per-Entity] adding a layer to the security model, Cantor, Scott, 09/21/2016
- Re: [Per-Entity] adding a layer to the security model, Tom Scavo, 09/21/2016
- Re: [Per-Entity] adding a layer to the security model, Cantor, Scott, 09/21/2016
- Re: [Per-Entity] adding a layer to the security model, Nick Roy, 09/21/2016
- Re: [Per-Entity] adding a layer to the security model, Cantor, Scott, 09/21/2016
- Re: [Per-Entity] adding a layer to the security model, Tom Scavo, 09/21/2016
- Re: [Per-Entity] adding a layer to the security model, Cantor, Scott, 09/21/2016
- Re: [Per-Entity] adding a layer to the security model, Tom Scavo, 09/21/2016
- Re: [Per-Entity] adding a layer to the security model, Cantor, Scott, 09/21/2016
Archive powered by MHonArc 2.6.19.