Shibboleth without artifact queries and artifact resolution

Wessel, Keith William kwessel at illinois.edu
Fri Dec 14 14:36:10 EST 2012


All,

Wondering if anyone else has tried this and what kind of results we might expect.

As it appears that Terracotta 3.7 no longer has the tim-tomcat-6.0 integration module, we're evaluating other options for our IDP cluster. One is implementing some or all of OSU's stateless clustering solution that Scott has done a great job on.

But we're also considering a more lazy solution. Since we'll have a new external auth mechanism behind Shib in the coming months, we don't want to put too much work into something that we'll just end up replacing. So, we're considering just enabling sticky sessions on our SLB, ensureing SSO as long as a user doesn't happen to hit the IDP after the node they already used goes down but before their IDP session would have expired and they'd have to log in again, anyway.

Other than the potential future SLO route, looks like we're going to miss out on artifact resolution and, unless we implement support for the shared secret and CryptTransientIDs, some attribute queries. However, it doesn't look like anyone other than folks snooping and Google bots are even hitting these profile handlers.

Have others set up this model without issues?

Can I assume that, if our IDP is configured to send all attributes on the front channel initially, we don't need to support attribute queries based on transient ID?

Are there other things I should be thinking about here? Just thought it best to ask the community before I shoot myself in the foot.

Thanks for any advice,
Keith

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20121214/2b644f73/attachment.html 


More information about the users mailing list