Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

At the November TAC F2F, we discussed having a matrix of best practices by which to evaluate registered sites to help set expectations and create peer pressure. This is a preliminary set of suggested criteria.

Policy

Technical Basics

  • Metadata Consumption
    • refresh metadata daily
    • verify the XML signature
    • check the expiration date
  • X.509 Certificates in Metadata
    • use of self-signed certificates with 2048-bit keys
    • no unexpired certificates in metadata
  • User Interface Elements in Metadata
  • Requested Attributes in SP Metadata
  • SAML 2.0 Support
    • IdPs with TLS-protected HTTP-Redirect SSO
    • SPs that support SAML 2.0 should indicate so in metadata
    • SPs with TLS-protected HTTP-POST ACS and an encryption key
  • SAML 1.1 Support
    • SPs with TLS-protected HTTP-POST ACS

...