Advice on planned IdP configuration changes associated with implementing SAML 2
Jan Keirse
jan.keirse at tvh.be
Wed Sep 11 10:49:46 EDT 2013
Hello,
On Wed, Sep 11, 2013 at 4:25 PM, Julian Williams
<julian.williams at it.ox.ac.uk> wrote:
> We are planning to go ahead with an update to our IdP's metadata next week to include the SAML2 profiles (currently we are only publishing the 1.1 profiles). As you can appreciate this is long overdue but the last time it was attempted here (2011) we had problems with a number of SPs/applications and had to back-out the change. The problems we had last time seem to be associated with the eduPersonTargetedID not being provided in SAML2 connections.
>
> Unfortunately further progress has been stalled until recently because it's been difficult to arrange testing of other 3rd party applications against our test IdP.
Assuming you have an account that has access to the 3rd party
applications through the regular IDP, it should not be very hard to
test with a test IDP. What I do when I plan big changes is to set up a
VM with the exact same configuration, hostname, certificates,... as
the live IdP. Because the host is not in the DNS server configuration
nobody uses this VM. After making the configuration change to the VM I
change my /etc/hosts or C:\Windows\System32\drivers\etc\hosts file so
that the hostname of the real IdP points to the VM. I can then log in
to all SP's with that VM to verify the config is valid.
--
**** DISCLAIMER ****
http://www.tvh.com/newen2/emaildisclaimer/default.html
"This message is delivered to all addressees subject to the conditions
set forth in the attached disclaimer, which is an integral part of this
message."
More information about the users
mailing list