Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Producing SAML metadata should be easier #1

Open
harrdou opened this issue Jun 13, 2018 · 0 comments
Open

Producing SAML metadata should be easier #1

harrdou opened this issue Jun 13, 2018 · 0 comments
Labels
enhancement New feature or request SAML Issue related to the SAML profiles

Comments

@harrdou
Copy link
Collaborator

harrdou commented Jun 13, 2018

Federation members (RPs and CSPs) only need to produce new metadata once every few years. Under the current process, the onus is on federation members to produce and digitally sign CATS-compliant metadata, and then submit it to Shared Services Canada (SSC) for review and distribution.

Federation members only produce new metadata every couple of years, making it very difficult to remember how to produce "perfect" metadata on the first try. More often than not, there are problems with the metadata that need to be corrected before it can be accepted. This causes a lot of wasteful back-and-forth interaction between the federation member and SSC.

I propose a change to the process so that SSC, as federation operator, would take care of signing the metadata. This has a number of benefits:

  1. SSC could make any minor corrections to the metadata needed to make it CATS-compliant. The SSC team deals with SAML metadata on a regular basis so there is no problem remembering how to do it.
  2. Having SSC sign the metadata provides a better indication of trust and authenticity compared to the current practice of using "self-signed" metadata.
  3. SSC, as metadata registrar, could implement the SAML V2.0 Metadata Extensions for Registration and Publication Information.
@harrdou harrdou added enhancement New feature or request SAML Issue related to the SAML profiles labels Jun 13, 2018
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request SAML Issue related to the SAML profiles
Projects
None yet
Development

No branches or pull requests

1 participant