Migrating Idp from 1.x to 2.x
Cantor, Scott
cantor.2 at osu.edu
Wed Feb 22 15:48:26 GMT 2012
> FWIW, we used the "stand up a new IdP with a new entityID" strategy to
> go from 1.3 to 2.1 and it worked fine for us. We had a couple of things
> going for us though:
>
> - Both the old and new IdPs used our local web SSO mechanism, which
> allowed for single signon between the IdPs
That's a key point.
> - We only had a few "federation" customers (i.e. SPs relying on our
> InCommon metadata), so we were able to coordinate with them so they
> could prepare for our entityID change
>
> - The other SPs could switch whenever they felt like it by grabbing our
> new metadata and referencing our new entityID (subject to a deadline of
> course ;)
I would agree that a lot of the pluses and minuses will depend on your SPs. I had 200+ using the InCommon metadata when I upgraded, and nothing using a private copy.
Something I have asked InCommon to do that will *greatly facilitate* testing SAML 2.0 rollouts is to allow us to specify SAML 2.0 protocol support without actually adding SAML 2.0 endpoints. That keeps any existing SP using SAML 1.1, but allows SAML 2.0 in an IDP-initiated fashion for testing.
-- Scott
More information about the users
mailing list