minimal/no backchannel shibboleth idp configuration
Tom Scavo
trscavo at gmail.com
Tue Dec 16 06:41:34 EST 2014
On Mon, Dec 15, 2014 at 10:05 PM, Paul B. Henson <henson at csupomona.edu> wrote:
> We're in the middle of changing our domain name (which has been lots of fun 8-/), and as part of that we're deploying separate idp's for the new domain. I'd like to take the opportunity to improve our configuration in ways that would have been difficult to do live on the existing implementation, including not implementing the back channel and minimizing what is advertised in metadata.
>
> I remember earlier this year being directed to a wiki page discussing this very topic, but cannot find it again :(. I think it was an Incommon or Internet2 page, which discussed the various endpoints that might be advertised in metadata and the minimal set needed for basic functionality. Does anybody know of the page I'm thinking of?
Searching for "back channel" in the Spaces wiki leads to this page:
https://spaces.internet2.edu/x/8YLYAg
However, the above isn't really a shib user issue...the only reason I
replied to this mailing list is to remind folks that the recommended
configuration for the IdP moving forward will become even more
complex, with separate keys for signing, encryption, and back channel.
There are good reasons for this, as discussed in this excellent new
wiki page: https://wiki.shibboleth.net/confluence/x/VoEOAQ
(I don't have any inside information, I've just been following the
discussion on the dev list, so my take on this may be less than
accurate...I'm sure someone close to the project will correct me if
I'm wrong :)
Tom
More information about the users
mailing list