Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: Reverted from v. 2

...

  • The search capalities should be extended to also cover searches for protocol (SAML1/SAML2/...), Interfederated (no, eduGAIN, Kalmar, ...), Code-of-Conduct (yes, no), Operated in a country that has an EU-like Dataprotection (yes,no). (Lukas Hammerle, SWITCH, Driver Restore)
  • support of SP key rollover in multiple federations. We've got a customer who has started the key rollover process in the UK federation, but this has caused problems in other federations when they started signing with a key that was only in our aggregate. So is it possible to compare metadata registrations that an entity has in different federations, specifically the embedded certificates and any use constraints? MET showed me which federations the SP is registered in (thanks!), but I still needed to hunt around for the other federations' metadata aggregate files. Reporting a link to the federations' aggregates, and the time that each metadata aggregate was queried by MET, would allow this function to be used in real-time to assist incident resolution. I've mocked up a page with the information that would prove useful to me (and I hope SP operators). It's at http://dlib-shandon.ucs.ed.ac.uk/2013-01-28-met-certificate-example.htm (Alex Stuart, UK Federation)

...