Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

The metadata submitted by the site administrator is vetted and approved by the InCommon Registration Authority (RA). Since the security of the SAML protocol depends on the proper use of metadata, the RA checks the correctness and integrity of what is submitted by the site administrator. In particular, the RA checks that the certificates and endpoints in metadata meet certain basic requirements. For instance, all URIs in metadata are expected to be rooted in the primary DNS domain of the submitting organization. If not, a manual vetting process is triggered.

Note

Read an important announcement announcements on Upgrading Weak Keys in Metadata and Dead Entities in Metadata

Federation Manager

A web interface called the Federation Manager is used to administer InCommon metadata. The interface supports both IdP and SP metadata. The elements of each are referenced in the following sections.

...

Note

New IdPs in Metadata must meet some basic requirements before their metadata can will be submittedapproved

IdP Metadata Elements

The following elements are called out in IdP metadata.

...