Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

InCommon strongly recommends that you refresh your metadata daily to ensure that your SAML endpoints have access to the most up-to-date keys and other registered information. Some software implementations (such as Shibboleth) handle metadata with ease, but please read this entire page to understand the requirements and pitfalls of associated with metadata consumption.

If you don't refresh your metadata regularly, it is likely your software implementation will fail at some point since the XML document carries an expiration date (validUntil) that causes the metadata to expire in three weeks. InCommon strongly recommends that you do not rely on the length of this validity interval in any way, and in fact, we reserve the right to shorten the validity interval with little or no notice.

...

To bootstrap the trust fabric of the Federation, participants are required to download (and verify in whatever manner deemed sufficient) the following certificate, which contains the public key corresponding to the Federation's private metadata signing key:

https://wayf.incommonfederation.org/bridge/certs/incommon.pem

Participants should validate this certificate in whatever manner is deemed appropriate. Once this certificate file is locally installed, you can use it to verify the signature on the metadata file in conjunction with the refresh process.

...

If you plan on using the Shibboleth software for the purposes of federation, you can in fact also use Shibboleth to download and verify the signed metadata without having to rely on any other tools. Regardless of your implementation, however, you can always set up a cron job to refresh your metadata, but in that case you will also need a tool to verify the XML signature at the time of refresh.

Apart from this refresh process, your software implementation needs to be configured to consume the InCommon metadata. Exactly how this is done depends on your implementation of course. Check the links below to learn Instructions how to do this with configure the Shibboleth software .

...

for metadata consumption are provided elsewhere in this wiki. Also, see the resources linked below for related information.

For More Information