canada-ca / canada-ca/CATS-STAE

Producing SAML metadata should be easier

Open
#1 0 comments 0 reactions 0 assignees View on GitHub
enhancement SAML
Dominant language
Shell
Stars
16
Forks
1
PR merge metrics
No merged PRs in 30d

Description

Federation members (RPs and CSPs) only need to produce new metadata once every few years. Under the current process, the onus is on federation members to produce and digitally sign CATS-compliant metadata, and then submit it to Shared Services Canada (SSC) for review and distribution.

Federation members only produce new metadata every couple of years, making it very difficult to remember how to produce "perfect" metadata on the first try. More often than not, there are problems with the metadata that need to be corrected before it can be accepted. This causes a lot of wasteful back-and-forth interaction between the federation member and SSC.

I propose a change to the process so that SSC, as federation operator, would take care of signing the metadata. This has a number of benefits:

1. SSC could make any minor corrections to the metadata needed to make it CATS-compliant. The SSC team deals with SAML metadata on a regular basis so there is no problem remembering how to do it.
2. Having SSC sign the metadata provides a better indication of trust and authenticity compared to the current practice of using "self-signed" metadata.
3. SSC, as metadata registrar, could implement the [SAML V2.0 Metadata Extensions for Registration and Publication Information](http://docs.oasis-open.org/security/saml/Post2.0/saml-metadata-rpi/v1.0/cs01/saml-metadata-rpi-v1.0-cs01.html "Link to OASIS").

Contributor guide

Open the contributing guide

Research direction

No files, tests, or entry points are identified. Start by reviewing how CATS-compliant SAML metadata is currently produced, signed, submitted, and distributed, then determine where the proposed SSC signing workflow belongs. Done would require an agreed implementation and process for SSC to correct, sign, and publish member metadata.

Written by the indexing model from the issue text.

Assessment

Tech stack
shell, xml
Domain
authentication, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.