Skip to Content.
Sympa Menu

streamlining-sp - Re: Streamlining SP Working Grouper - meeting reminder

Subject: Streamlining SP Onboarding WG

List archive

Re: Streamlining SP Working Grouper - meeting reminder


Chronological Thread 
  • From: Nick Roy <>
  • To: Garrett King <>, "" <>
  • Subject: Re: Streamlining SP Working Grouper - meeting reminder
  • Date: Fri, 19 Jan 2018 18:51:59 +0000
  • Accept-language: en-US
  • Authentication-results: spf=none (sender IP is ) ;
  • Ironport-phdr: 9a23:8lVP8h+8G1ZdCP9uRHKM819IXTAuvvDOBiVQ1KB20u0cTK2v8tzYMVDF4r011RmVBdyds6oMotGVmpioYXYH75eFvSJKW713fDhBt/8rmRc9CtWOE0zxIa2iRSU7GMNfSA0tpCnjYgBaF8nkelLdvGC54yIMFRXjLwp1Ifn+FpLPg8it2O2+54Dfbx9UiDahfLh/MAi4oQLNu8cMnIBsMLwxyhzHontJf+RZ22ZlLk+Nkhj/+8m94odt/zxftPw9+cFAV776f7kjQrxDEDsmKWE169b1uhTFUACC+2ETUmQSkhpPHgjF8BT3VYr/vyfmquZw3jSRMNboRr4oRzut86ZrSAfpiCgZMT457HrXgdF0gK5CvR6tuwBzz4vSbYqINvRxY7ndcMsaS2RfQ8hRSyJPDICyb4sOE+UPMulXopLhp1sXsReyGRWgCP/vxzJOm3T43bc60+MkEQzexAIgHs4BsHfJp9vpM6cTUf2+wa7OzTXZaPNX2Szw6InOchA9v/6MR7RwftTNyUUxDQ/KkEifqZH8Mj6Ty+8DsHCb4vJ9We6zhGMrsQ58rzq1ysojlIXFnJ8Zxk3K+Clhwos4K8e0RFN0bNK+DZdcqiGXO5FrTs4gXm1lvjsxxKcctp6hZicKzYwqxx7BZPyDdIiF+grtWfqWLztkin9pYa+yiBSs/US5ze3zTde73ExNripYjtnDrXcN1wHV6seaUPd95l2h2TGT1w/N9u5EPUE0la3dK5I7xb4wi4YTsUDEHi/xm0X6lrOZdkIh+uSw6uTnZKvppoOEOoNplg3zPb4il8O9DOgiPQUCQXKX9fmh2LDt5UH5Ra9FjvwykqnXqpDaIsEbq7a/Aw9P1YYi6w2yDzag0NQEg3YHNlRFdwybj4T3IV3BPu33Deqnj1S2jDhr3+zGPqHmApjVL3jDlqvufbF4605Zzwozy8pT55VOCrEOOf7zQVPxtMbGARAjNgy0x+fnCNN81oMYVmKDG7SZMLvJvF+M5+IvOPWMZJQLtDrnKvgl4eLugmEjmV8bY6apwYUbZGqmEft7PkXKKUbr1/gIC30HohZ2b+3shxXWXjdJfXuuQ6EU7TQmTo+qENGHDsq2nKaM1SK/H5tXYG8DEUikEHHjcICBXPFKbzidaIc1iSAeWLGkT44n1Beh8RTi47thJe3R/yoe85X5244myffUkEQU9Dd3R/6awinZSXtzj0sJQSM7xqZyvRY7x1ueh/sry8dEHMBesqsaGjwxMoTRmqkjU4j/
  • Spamdiagnosticmetadata: NSPM
  • Spamdiagnosticoutput: 1:99

Thank you Garrett, much appreciated.

Nick

On 1/19/18 9:29 AM, Garrett King wrote:
> Hi Nick,
>
> I agree.  I’ll add this to the next WG agenda to make sure we’re
> accounting for this in the criteria document and calling it
> appropriately (per your example) in the questionnaire.
>
> Thanks for the feedback,
> Garrett
>
> On Jan 18, 2018, 1:23 PM -0500, Nick Roy
> <>,
> wrote:
>> I should note that sites that refresh metadata but do not verify the
>> signature are putting themselves and all of their federation partners at
>> great risk. This is fundamental to our security model. Please let me
>> know if you have any questions or would like me to elaborate.
>>
>> Best,
>>
>> Nick
>>
>> On 1/17/18 2:57 PM, Nick Roy wrote:
>>> Hi all,
>>>
>>> I have one piece of feedback on the questionnaire: could you please
>>> include a question about metadata signature verification in the "Trust"
>>> section?
>>>
>>> Something along the lines of:
>>>
>>> "Does your site verify the XML digital signature on the root element of
>>> the downloaded InCommon metadata each time you refresh metadata, to
>>> ensure that the signature is valid, and was signed by the private key
>>> that corresponds to the public key published by InCommon operations, and
>>> reject any metadata found to not be validly signed?"
>>>
>>> Thank you,
>>>
>>> Nick Roy on behalf of InCommon Operations
>>>
>>>
>>> On 1/17/18 2:39 PM, Garrett King wrote:
>>>> Thanks Alan, and agreed with your comments.  I’ll get some of this
>>>> feedback incorporated between this week and the next WG meeting.
>>>>
>>>> Garrett
>>>>
>>>> On Jan 17, 2018, 5:16 AM -0500, Alan Buxey
>>>> <>,
>>>> wrote:
>>>>> hi, apologies in advance, I won't be able to make todays meeting -
>>>>> kids things to deal with (nothing serious/worrying etc - just mundane
>>>>> things)
>>>>>
>>>>> however, to further the questionnaire discussion and provide feedback
>>>>> - having gone through the form a couple of times, I would say that
>>>>> some of the stuff that appears on the no/don't know page should be
>>>>> moved to the previous page - so that there's some info or 'more info'
>>>>> link
>>>>> on the actual question page - allowing the user to understand or check
>>>>> before they choose an option. eg link to InCommon certificate
>>>>> requirements
>>>>>
>>>>> alan
>>>



Archive powered by MHonArc 2.6.19.

Top of Page