IdP cleanup

Terence Schlacter tschlact at gmail.com
Wed Jan 30 08:37:15 EST 2013


Hello list,
we want to remove some features from our IdP for a number of reasons
(mostly, they are unused; and we are building a "reverse proxy-based"
cluster with no session sharing between nodes).

So we'd like to remove any backchannel service, and shibboleth1 protocol
support.

To start with, we removed any AttributeQuery and ArtifactResolution
reference (both SAML1 and SAML2) from handler.xml.
>From the IDP Metadata we removed the whole AttributeAuthorityDescriptor
section among with the ArtifactResolutionService bindings in the
IDPSSODescriptor section.

Is that enough to remove any backchannel support from the default setup?

For what matters removal of shibboleth 1 protocol: we also deleted the
ShibbolethSSO profile from handler.xml and the PrincipalConnector and
AttributeEncoder for shibboleth:1.

Should we remove the shibboleth:1 entry from handler.xml as well?
Is it just enough to clear any shibboleth:1 reference into the IDP metadata
file or there is any caveat we should be aware of?

Thank you very much
--
Terence Schlacter
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130130/5d50f0ec/attachment.html 


More information about the users mailing list