Would someone sanity-check my metadata before I submit it to InCommon?
Ken Weiss
ken.weiss at ucop.edu
Wed Jan 22 14:14:17 EST 2014
I know this is asking a lot, and worst case I'll just submit it and hope
for the best, but I am a newbie to Shibboleth and have no immediate
co-workers that are experts to look over my shoulder. I would really
appreciate it if someone else could review my metadata and tell me if it
appears to be valid and likely to result in a system that behaves as I
would like.
My goal is to set up one EntityDescriptor that can be used to facilitate
our migration from version 1 of the DMPTool service to version 2. I
believe I can accomplish this by adding additional DiscoveryResponse and
AssertionConsumerService elements to the existing entityID of
https://dmp.cdlib.org, some of which currently will point to hosts that
are running version 1 of the service, and some of which are running
version 2. By changing the target hosts for the DNS aliases used by the
general public, I hope to be able to begin by running both v1 and v2 in
parallel, and then start sending all requests to v2, at which point we can
shut down the hosts that run v1 and remove all references to those hosts
from the metadata. I would like all this to happen with no need to revise
the published metadata.
We have two actual hosts, cdl-dmp-p01.ucop.edu and cdl-dmp2-p01.ucop.edu.
Aliases exist as follows:
cdl-dmp-p01 is the actual host resolved by:
dmp.cdlib.org
dmptool.org
v1.dmptool.org
cdl-dmp2-p01 is the actual host resolved by:
dmp2.cdlib.org
dmp2-production.cdlib.org
v2.dmptool.org
My plan is to shift the dmp.cdlib.org and dmptool.org aliases so they
resolve to cdl-dmp2-p01 once testing is completed and we want to make a
hard cutover to the new version. My goal is for this one metadata set to
work for federated authentication regardless of which actual host those
aliases resolve to.
I realize that I will need to make the sp-cert.pem and sp-key.pem files
for my SPs the same on cdl-dmp-p01 and cdl-dmp2-p01, and that these must
match the one that is in my metadata. I will also have to set the target
EntityID in shibboleth2.xml to the same value on both hosts.
I am particularly concerned about the DiscoveryResponse elements. Do these
work just like AssertionConsumerService elements, in that Shibboleth will
send the user back to the same URL root they came in with, provided it
exists as one of the elements? That was my assumption when I drafted this
metadata.
Anyway, rather than clutter up the list, I put my metadata here...
http://pastebin.com/G93R18Lk
If anyone can take the time to review it for me, that would be great.
Thanks in advance.
--Ken
------------------------------------------------------------
Ken Weiss ken.weiss at ucop.edu
UC Office of the President 510-587-6311 (office)
California Digital Library 916-905-6933 (mobile)
UC Curation Center
415 20th Street, 4th Floor
Oakland, CA 94612
More information about the users
mailing list