Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

In addition, if you don't refresh your metadata regularly, it is likely that a software implementation will fail at some point since the XML document carries an expiration date (validUntil) that causes the metadata to expire in approximately two weeks. InCommon strongly recommends that you do not rely on the actual length of this validity interval in any way, and in fact, we reserve the right to shorten the validity interval with little or no notice.

Metadata Refresh Process

The mechanics of Here are the steps to deploy a secure, automated metadata refresh process:

  1. Choose the right metadata aggregate for your particular deploymentone of three Metadata Aggregates
  2. Download an authentic copy of the Metadata Signing Certificate
  3. Deploy and configure an automated metadata refresh process:
    1. Install and configure your metadata client software Metadata Client Software
    2. Validate the expiration date on downloaded metadata
    3. Verify the XML signature on downloaded metadata
  4. Adjust your outbound firewall rules (if necessary)

...

Depending on your environment, you may have to poke a hole in an outbound firewall to allow your metadata client to reach the metadata server. In that case, you will actually want to poke two holes in that firewall since there are two physical servers as described on the Metadata Server wiki page.

...