Migrating Idp from 1.x to 2.x
Christopher Bongaarts
cab at umn.edu
Wed Feb 22 15:39:41 GMT 2012
On 2/22/2012 8:51 AM, Cantor, Scott wrote:
>> Any thoughts?
>
> My thoughts are captured in the wiki under upgrade strategies, and
> you'll find I recommend a fundamentally different approach. It went
> exactly as expected at OSU without a hitch, so nothing's changed my
> mind. I don't think using two IdPs makes sense, and I don't think you
> want to be trying to segregate old and new.
FWIW, we used the "stand up a new IdP with a new entityID" strategy to
go from 1.3 to 2.1 and it worked fine for us. We had a couple of things
going for us though:
- Both the old and new IdPs used our local web SSO mechanism, which
allowed for single signon between the IdPs
- We only had a few "federation" customers (i.e. SPs relying on our
InCommon metadata), so we were able to coordinate with them so they
could prepare for our entityID change
- The other SPs could switch whenever they felt like it by grabbing our
new metadata and referencing our new entityID (subject to a deadline of
course ;)
For our 2.1 to 2.3 upgrade last week, we configured the new instance so
the previous metadata would work, and just flipped machines in the load
balancer.
--
%% Christopher A. Bongaarts %% cab at umn.edu %%
%% OIT - Identity Management %% http://umn.edu/~cab %%
%% University of Minnesota %% +1 (612) 625-1809 %%
More information about the users
mailing list