eosc-kc / keycloak

Open Source Identity and Access Management For Modern Applications and Services
https://www.keycloak.org
Apache License 2.0
4 stars 4 forks source link

Enable expiration of entities imported from SAML aggregates #34

Open NicolasLiampotis opened 3 years ago

cgeorgilakis commented 3 years ago

As I see from https://md.aai.grnet.gr/feeds/edugain-idp-samlmd.xml validUntil exists only for SAML Federation. LastUpdated of SAML Federation is almost ever before validUntil. Should we do this issue? If yes, we should discuss functionality.

cgeorgilakis commented 3 years ago

Federation medatadata are updated every x time. If during metadata update, valid until of md:EntitiesDescriptor is before current time, IdPs are disabled.