Migrating Idp from 1.x to 2.x

Christopher Bongaarts cab at umn.edu
Wed Feb 22 15:39:41 GMT 2012


On 2/22/2012 8:51 AM, Cantor, Scott wrote:
>> Any thoughts?
>
> My thoughts are captured in the wiki under upgrade strategies, and
> you'll find I recommend a fundamentally different approach. It went
> exactly as expected at OSU without a hitch, so nothing's changed my
> mind. I don't think using two IdPs makes sense, and I don't think you
> want to be trying to segregate old and new.

FWIW, we used the "stand up a new IdP with a new entityID" strategy to 
go from 1.3 to 2.1 and it worked fine for us.  We had a couple of things 
going for us though:

- Both the old and new IdPs used our local web SSO mechanism, which 
allowed for single signon between the IdPs

- We only had a few "federation" customers (i.e. SPs relying on our 
InCommon metadata), so we were able to coordinate with them so they 
could prepare for our entityID change

- The other SPs could switch whenever they felt like it by grabbing our 
new metadata and referencing our new entityID (subject to a deadline of 
course ;)

For our 2.1 to 2.3 upgrade last week, we configured the new instance so 
the previous metadata would work, and just flipped machines in the load 
balancer.

-- 
%%  Christopher A. Bongaarts   %%  cab at umn.edu          %%
%%  OIT - Identity Management  %%  http://umn.edu/~cab  %%
%%  University of Minnesota    %%  +1 (612) 625-1809    %%


More information about the users mailing list