Question about AssertionConsumerService endpoints
Peter Schober
peter.schober at univie.ac.at
Wed Jan 22 12:27:09 EST 2014
* Ken Weiss <ken.weiss at ucop.edu> [2014-01-22 18:22]:
> I was just getting ready to simplify my metadata by setting up a single
> EntityDescriptor with endpoints defined for all of my physical and virtual
> hosts when I realized there is a potential issue.
>
> Each host has its own instance of Shibboleth SP running. Each instance of
> Shibboleth SP has its own certificate. Unless I make all the certificates
> the same, only the SP with the certificate that matches what's in the
> metadata will work.
I thought about mentioning this the other day but figured you'll know
this already. Anyway, if those systems are close enough in their
function and management that you'll consider given them all the same
entitID I don't see a problem given them all the same key pair.
You'll likely be doing the same with their (unrelated!) TLS/SSL keys,
I'm guessing (unless you're terminating TLS/SSL on some load balancer
anyway, of course).
-peter
More information about the users
mailing list