Skip to Content.

edugain-discuss - Re: [eduGAIN-discuss] MDS re-publishes schema-invalid metadata

edugain-discuss AT lists.geant.org

Subject: An open discussion list for topics related to the eduGAIN interfederation service.

List archive


Re: [eduGAIN-discuss] MDS re-publishes schema-invalid metadata


Chronological Thread 
  • From: Nick Roy <nroy AT internet2.edu>
  • To: Peter Schober <peter.schober AT univie.ac.at>
  • Cc: "edugain-discuss AT lists.geant.org" <edugain-discuss AT lists.geant.org>
  • Subject: Re: [eduGAIN-discuss] MDS re-publishes schema-invalid metadata
  • Date: Tue, 24 Sep 2019 19:18:32 +0000
  • Accept-language: en-US
  • Arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=internet2.edu; dmarc=pass action=none header.from=internet2.edu; dkim=pass header.d=internet2.edu; arc=none
  • Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=aMbCiwqQowLiFmqdhE+DMmlZTlKOO93mFOO9Rx2VNio=; b=EX1kM4N0zBdOXnpGXZylTmaf0ZpwzhYO9EucCbsNEJdSngZUJFoPvDnUWaP/lQrXtF9ikbKtY+PoZI5QmfEywBYsbFA/am14EKVbHz0mHtnx3OVfvz4sakvmQ7a4Wukj2tBYM2LCPlFN2gFSwUhLFOhhcPH4qWltvde/jaqZHVV/58Lf0vQBhy436emyGR44yKV2qlnaQ36fUnrNY8hnycshT4Tr3kd5zWEBb+B87FmmFh9r9b1stwxVlVaypCsiKLbGdAHDgG29d2UloA+EUkfrYmXUEC1kYnuj5XIBbIFcnl33mdtq9JNVUttl4efCe+1SshDhIitwZc2jYRMAjg==
  • Arc-seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=hA9N7+8cQwjq4G8gP8r+z26egkrvZXzSJHpZ0iXxXAIsbiXsipBrp9EBpTRzH+NeTKkMVRXq/FIdZZTG4KvuIPyTQsWaQ9qSRhVHmzQXN/okJTMGdWH0j7qPmnJFT+FinNkFn3Fuhua6aohOwgHc0oyccrh5v3HkLSI0SMnliArjWOuwPvb6by17DN2HcfEpfDvrVtabbdBk+cwev3/4zVz1MyGIS94ZXo9Ej3JKhUjBfcGCoafauvbxtEyJsRduRcGJEKloHl1XLdBfULOp1AgD1T88rmi5UKnjjXZiUq++3fh0Qgo4PkCUDpplu5TmN+J+uhm1LkvjQDbi4Ms8kw==
  • Authentication-results: spf=none (sender IP is ) smtp.mailfrom=nroy AT internet2.edu;

"A protocol should be conservative in its transmissions and clients should be
liberal in their acceptance of incoming messages." or words to that effect. -
Jon Postel.

Nick

On 23 Sep 2019, at 16:32, Peter Schober wrote:

> * Tomasz Wolniewicz <twoln AT umk.pl> [2019-09-23 22:12]:
>> eduGAIN validator was using a newer xml.xsd and the validation passed.
>>
>> So what is the correct approach here?
>
> As I said, the current Shibboleth SP release fails to load such
> metadata. Sure, we can try to get that changed upstream and then wait
> a few years until it's deployed everwhere where a Shib SP is running
> today, hoping such XML will never occur in the meantime. And even when
> it does and things break (SPs failing to update, leading to expired
> metadata days or weeks later) we can still tell the SP owners that
> we've let this error (or "former error") through on purpose because we
> don't consider it an error any more and they should get their software
> fixed. Let's see how that goes.
>
> Or... we could be as conservative as possible in what we publish to
> avoid any such breakage (to me that means not being liberal in what I
> accept, too), esp. in cases that make no sense at all (such as empty
> xml:lang="" XML attributes or other effects of improper tooling or
> human errors, not concious decisions that the XML should in fact look
> exactly like that).
>
> But I've already made those choices for my (or our federation), it's
> up to us all to decide how the MDS should behave being the man in the
> middle. If the MDS allows it that doesn't mean we can't filter it out
> in our local feeds, that merely raises the bar a bit further what it
> means to particiate in eduGAIN for member federations.
>
> Cheers,
> -peter [ offline for the next days ]

Attachment: signature.asc
Description: OpenPGP digital signature




Archive powered by MHonArc 2.6.19.

Top of Page