how to upgrade idp 1.3 to idp2.x?

Cantor, Scott cantor.2 at osu.edu
Wed May 16 17:44:35 BST 2012


On 5/16/12 12:21 PM, "XiaoXia Dong" <x-dong at northwestern.edu> wrote:

>I would like to ask a follow up question: Would it be possible just set
>up a new Shib Idp 2.x and then add those new end points in the InCommon
>metadata,
>So that we could bring both of these two versions of IdP in production.
>Then SP users could test their instances against IdP 2.x at their own
>time. Will this work from your experience?

I think it's a bad model, and InCommon doesn't encourage it, but your
question should really be directed to uncommon-admin, not this list.

Using a second IdP means changing your entityID and essentially
reconfiguring lots of services to use it, and also potential changes to
policies and even attribute values in some cases. You're inflicting your
upgrade on every SP, and I think that's a bogus way to go about the
situation. Software upgrades require work, and it should be your work, not
somebody else's. But I'm known as a serious complainer about this issue.

>What difference of end points between IdP 1.3 and IdP 2.x?  Would you be
>able to give an example? Thanks.

No, I'm not going to type them all out. Just run both and compare the
endpoints for various profiles. Heck, look in metadata like InCommon's and
you'll see lots of examples of both.

-- Scott



More information about the users mailing list