Skip to Content.
Sympa Menu

streamlining-sp - Re: Streamlining SP Working Grouper - meeting reminder

Subject: Streamlining SP Onboarding WG

List archive

Re: Streamlining SP Working Grouper - meeting reminder


Chronological Thread 
  • From: Nick Roy <>
  • Cc: "" <>
  • Subject: Re: Streamlining SP Working Grouper - meeting reminder
  • Date: Thu, 18 Jan 2018 18:23:22 +0000
  • Accept-language: en-US
  • Authentication-results: spf=none (sender IP is ) ;
  • Ironport-phdr: 9a23:m4eWUhZPcmhgmSomxN8n3JT/LSx+4OfEezUN459isYplN5qZr82zbnLW6fgltlLVR4KTs6sC17KP9fi4EUU7or+5+EgYd5JNUxJXwe43pCcHRPC/NEvgMfTxZDY7FskRHHVs/nW8LFQHUJ2mPw6arXK99yMdFQviPgRpOOv1BpTSj8Oq3Oyu5pHfeQpFiCagbb9oMBm6sRjau9ULj4dlNqs/0AbCrGFSe+RRy2NoJFaTkAj568yt4pNt8Dletuw4+cJYXqr0Y6o3TbpDDDQ7KG81/9HktQPCTQSU+HQRVHgdnwdSDAjE6BH6WYrxsjf/u+Fg1iSWIdH6QLYpUjSn7qdrUwToiCYBNz427WrZlNV+h79VoBKguRN/x5Pba5yROPdwYq/ReNUXTndDUMlMTSxMGoOyYZYTD+QPPuhYoYj9qEcBoxSxHgSsGPrvxiNUinPqwaE30+IsGhzG0gw6GNIOtWzZos30NKgOUuC+0bXGzTLDbvhL3jr97pLIchchoPyXXLJwd9bRxlc1FwPDkFqQtZLpMymL2esQrmiW9uxtXv+shW4/swx9vySjy8g2hoTGhI8Z0F7J+CZjzIooONG1SVZ3bNyqHZdKqi2XOJF6Tt4/T2xooio2178LtYO9cSMX0poo3QTfZOaCc4WQ4hLsSuKRITBgiXx9ZL+xgAq+/Va5xuDhUMe4zk9Gri1endbSrHwN0AHT6tScRft640eh3yuA2xrL6uFeJkA0ibTUJII9wr4xkZoTt17PHijrmEXqiK+WcUIk+uuy5+v7ZbXmo4eQN45yig7gLqQjgtGzDfg3PwQUUGWW+/6w2bPg8EHjXblGk/w7nrHcsJ/AJMQboqC5AxVS0oYm8xu/CS2m0NMYnHQcLVJFfg6HgJbzO1HIPv/4Eemzj06ynzh22vDKJqfhDYnVLnjfjLfheq5w609ayAUvytBf4pdUCrYHIP7pXU/xrtPYAgYiMwyo2eboFs9y1oYaWWKOBK+ZMaXSsVCR6uI0O+mBf4sVuDfmK/g5/P7ik2U1mV4bfam1w5QXcna4Eep6I0mHe3bjnMoOEXpZ9iQkS+m/rlyJUnZpYGf6C6Qm4SATCYS6AJ3FS5z3xrGNwXHoTdVtemlaBwXUQj/TfIKeVqJXMC8=
  • Spamdiagnosticmetadata: NSPM
  • Spamdiagnosticoutput: 1:99

I should note that sites that refresh metadata but do not verify the
signature are putting themselves and all of their federation partners at
great risk. This is fundamental to our security model. Please let me
know if you have any questions or would like me to elaborate.

Best,

Nick

On 1/17/18 2:57 PM, Nick Roy wrote:
> Hi all,
>
> I have one piece of feedback on the questionnaire: could you please
> include a question about metadata signature verification in the "Trust"
> section?
>
> Something along the lines of:
>
> "Does your site verify the XML digital signature on the root element of
> the downloaded InCommon metadata each time you refresh metadata, to
> ensure that the signature is valid, and was signed by the private key
> that corresponds to the public key published by InCommon operations, and
> reject any metadata found to not be validly signed?"
>
> Thank you,
>
> Nick Roy on behalf of InCommon Operations
>
>
> On 1/17/18 2:39 PM, Garrett King wrote:
>> Thanks Alan, and agreed with your comments.  I’ll get some of this
>> feedback incorporated between this week and the next WG meeting.
>>
>> Garrett
>>
>> On Jan 17, 2018, 5:16 AM -0500, Alan Buxey
>> <>,
>> wrote:
>>> hi, apologies in advance, I won't be able to make todays meeting -
>>> kids things to deal with (nothing serious/worrying etc - just mundane
>>> things)
>>>
>>> however, to further the questionnaire discussion and provide feedback
>>> - having gone through the form a couple of times, I would say that
>>> some of the stuff that appears on the no/don't know page should be
>>> moved to the previous page - so that there's some info or 'more info'
>>> link
>>> on the actual question page - allowing the user to understand or check
>>> before they choose an option. eg link to InCommon certificate
>>> requirements
>>>
>>> alan
>



Archive powered by MHonArc 2.6.19.

Top of Page