Skip to Content.

edugain-discuss - Re: [eduGAIN-discuss] MDS re-publishes schema-invalid metadata

edugain-discuss AT lists.geant.org

Subject: An open discussion list for topics related to the eduGAIN interfederation service.

List archive


Re: [eduGAIN-discuss] MDS re-publishes schema-invalid metadata


Chronological Thread 
  • From: Molnár Péter <molnar.peter AT kifu.gov.hu>
  • To: edugain-discuss AT lists.geant.org
  • Subject: Re: [eduGAIN-discuss] MDS re-publishes schema-invalid metadata
  • Date: Tue, 24 Sep 2019 09:49:31 +0200



Le 2019. 09. 24. à 9:21, Peter Schober a écrit :
* Tomasz Wolniewicz <twoln AT umk.pl> [2019-09-24 09:07]:
One could even think the the correct approach is to have people
update their fairly ancient schemas rather disallowing something
that has been in the standard for 15 years.
See my statement about SPs deployed in the wild choking on such
metadata. It's not simply a question of "updating schemas" for a few
(or only one) federation operator:

This stuff breaks deployments in the wild and the Shibboleth SP
(should it be the only one) is probably the most often used SAML
implementation on the globe. So -- contrary to what Davide said -- I'm
very happy old schemata were used in the software I had at hand
otherwise we would only have found out about that in a few days (or
weeks) once Shib SP admins all over the world started asking their
local federation operator why their SP doesn't know any IDPs anymore.

"People should just update their software so that we can support
corner cases noone ever asked for" is a possible approach to such
scenarios. It's certainly not my preferred one, though.

-peter
For now, I think it can be a reasonable practice to introduce an empty lang attributes check in our federation.

--
Péter
eduID.hu




Archive powered by MHonArc 2.6.19.

Top of Page