-
IDP login and error page should be customised.
-
IDP Status URL should be monitored by HEAnet
-
IDP should publish authentication statistics for Cactii.
-
IDP should have a persistentID database (see the instructions for Windowsor Unix) and be capeable of providing nameid's in the persistent and transient format.
-
IDP should have uApprove or other consent module (see the uApprove installation guide)
-
IDP should re-publish its latest copy of the federation metadata to a URL
-
IDP should publish its own metadata to a URL
-
IDP should download metadata every 20 minutes
-
IDP should refresh config every 20 minutes of the following;
-
remotely hosted attribute-filter.xml
-
locally hosted attribute-resolver.xml (to avoid restarts)
-
-
IDP Operator should integrate IDP monitoring as follows;
-
LDAP connection
-
DB connection
-
IDP Status URLs
-
Diskspace
-
Access to edugate.heanet.ie/edugate-metadata-signed.xml
-
IDP SSL certificate expiry
-
-
IDP should handle connection timeouts to DB and LDAP gracefully
-
IDP should narrow LDAP search to required attributes only
-
IDP should produce eduPersonScopedAffiliations for at least staff and student rather than the single value of member. Alumni and affiliate values should also be produced. See Mapping the local schema to the Edugate schema
- RollingFileAppender should use .gz compression
- logging.xml should enable PROTOCOL_MESSAGE debug level.
- Logout should be supported

