Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

The rules marked red are actually specification errors and should be upgraded to validator errors (to be discussed within the eduGAIN SG)

GlobalEntity levelEntity’s role level

ConditionLevelSignificanceReason
1

Signing certificate expired

global1Currently implemented as a validator warning. To be confirmed by the SG.
2md:EmailAddress in md:ContactPerson element should start with mailto: prefixentity4This violates line 495 of https://docs.oasis-open.org/security/saml/v2.0/saml-metadata-2.0-os.pdf and should be considered an error!
3

SIRTFI attribute present and security contact found but no http://refeds.org/metadata/contactType/security contactType

entity2SIRTFI specification error
4

SIRTFI attribute declared but no appropriate md:ContactPerson set

entity2SIRTFI specification error
5

shibmd:Scope with no regexp attribute

entity5https://wiki.shibboleth.net/confluence/display/SC/ShibMetaExt+V1.0 recommendation
6

mdattr:EntityAttributes placed in md:Extensions element of SPSSODescriptor/IDPSSODescriptor, expected in  md:Extensions element of EntityDescriptor

entity
Since http://docs.oasis-open.org/security/saml/Post2.0/sstc-metadata-attr.html does not define appearance of this element in places other then md:Extensions element of EntityDescriptor it is most likely that the condition is a result of a mistake.
7

mdrpi:RegistrationPolicy not found

entity3eduGAIN SAML profile Section 3
8

mdattr:EntityAttributes element contains saml:AttributeValue with leading/trailing whitespaces

entity

9mdui:UIInfo not found, no mdui:DisplayName and mdui:Description presentrole
eduGAIN SAML profile Section 3
10mdui:UIInfo with mdui:DisplayName found but mdui:Description not presentrole
eduGAIN SAML profile Section 3
11mdui:UIInfo found but mdui:DisplayName not presentrole
eduGAIN SAML profile Section 3
12mdui:UIInfo found but neither mdui:DisplayName nor mdui:Description presentrole
eduGAIN SAML profile Section 3
13mdui:UIInfo found but no mdui:Logo elementrole
eduGAIN SAML profile Section 3
14this SP does not provide requested attribute specificationrole
left from saml2int - should it be kept?
15Data Protection Code of Conduct declared but no mdui:PrivacyStatementURL foundrole
Violates the CoCo spec
16CoCo declared but md:RequestedAttribute element not foundrole
Violates the CoCo spec
17CoCo declared but mdui:PrivacyStatementURL and md:RequestedAttribute elements not foundrole
Violates the CoCo spec