Any "gotchas" to adding in SAML 2 support?

Tom Scavo trscavo at gmail.com
Thu Jul 5 19:42:38 EDT 2012


On Thu, Jul 5, 2012 at 7:11 PM, Eric Goodman <ericg at ucsc.edu> wrote:
>
> We are running IdP 2.x, and we have been publishing SAML2 endpoints to
> several non-InCommon SPs.

What bindings do you support? Is HTTP-Redirect one of them?

> However, the metadata we currently publish through
> InCommon is all SAML1. We would like to add our SAML2 endpoints into our
> InCommon metadata.

That would be great :-)

> My question for the group is: are there any gotchas with doing this? After
> looking through the troubleshooting pages on the wiki, it seems like the
> most common mistake we could make is failing to update all of our relying
> party configs to support SAML2 before the SAML2 endpoints are published, but
> we're wondering if there are any other gotchas to look for on the IdP or SP
> before making the change.

Since you're already interoperating with a select group of SAML2 SPs,
I'm not sure what you're asking. Seems like all the hard work has
already been done.

One thing you might want to do is add an errorURL to metadata at the
same time you add the SAML2 endpoints. This will give first-time SPs
something to point the user at when they don't get the attributes they
want.

Btw, have you considered certifying the CGHub as a Research &
Scholarship SP? Seems like a good fit to me. Drop me a line at my
Internet2 e-mail address (in the cc line) and we can talk.

Tom


More information about the users mailing list