Ops Update 2017-03-02

  1. Message re Cloudbleed incident sent to inc-ops-notifications on Feb 27 (subscribe)
  2. Summary of recommendations re domains in IdP metadata:
    1. InCommon should relax its requirements on domains in IdP endpointsAn authorized site administrator should be allowed to submit an IdP endpoint with any domain whatsoever. The InCommon RA will neither vet nor validate the domains in IdP endpoints submitted to InCommon.
      1. InCommon should strongly recommend that the owner of the IdP also own the domains in IdP endpoints.
    2. InCommon should continue to enforce strict requirements on entityIDs in IdP metadata. See the Entity IDs wiki page (and its child pages) for details.
    3. InCommon should continue to enforce strict requirements on scopes in IdP metadata. See the Scope in Metadata wiki page for details.
  3. HTTPS-protected protocol endpoints
    1. Will introduce this topic on the mailing list
  4. Update: Signed per-entity metadata now produced daily
  • No labels