canada-ca / canada-ca/CATS-STAE
Producing SAML metadata should be easier
- Dominant language
- Shell
- Stars
- 16
- Forks
- 1
- PR merge metrics
- No merged PRs in 30d
Description
Federation members (RPs and CSPs) only need to produce new metadata once every few years. Under the current process, the onus is on federation members to produce and digitally sign CATS-compliant metadata, and then submit it to Shared Services Canada (SSC) for review and distribution.
Federation members only produce new metadata every couple of years, making it very difficult to remember how to produce "perfect" metadata on the first try. More often than not, there are problems with the metadata that need to be corrected before it can be accepted. This causes a lot of wasteful back-and-forth interaction between the federation member and SSC.
I propose a change to the process so that SSC, as federation operator, would take care of signing the metadata. This has a number of benefits:
1. SSC could make any minor corrections to the metadata needed to make it CATS-compliant. The SSC team deals with SAML metadata on a regular basis so there is no problem remembering how to do it.
2. Having SSC sign the metadata provides a better indication of trust and authenticity compared to the current practice of using "self-signed" metadata.
3. SSC, as metadata registrar, could implement the [SAML V2.0 Metadata Extensions for Registration and Publication Information](http://docs.oasis-open.org/security/saml/Post2.0/saml-metadata-rpi/v1.0/cs01/saml-metadata-rpi-v1.0-cs01.html "Link to OASIS").
Contributor guide
Research direction
No files, tests, or entry points are identified. Start by reviewing how CATS-compliant SAML metadata is currently produced, signed, submitted, and distributed, then determine where the proposed SSC signing workflow belongs. Done would require an agreed implementation and process for SSC to correct, sign, and publish member metadata.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- shell, xml
- Domain
- authentication, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100