DNS changes affecting SP endpoints

bmontgomery bmontgomery at teamdynamix.com
Mon Feb 2 15:10:51 EST 2015


We host a few different web applications on one IIS server. This server is
running Shibboleth SP. We want to take a couple of those applications and
move them to different servers, and those applications DO NOT need to be
secured via SSO. However, the applications that remain do. Part of this
process is moving the applications to a different box, but also changing our
"www" DNS entry such that it points at the new box (which does not have Shib
installed) instead of the current box. The challenge is that our service
provider endpoints are currently referencing the "www" subdomain.

What is the best way to transition to a new set of endpoints?

My plan was to configure Shib SP so that it will work for both "www" and
"shib" subdomains first for the assertion consumer services. Then we would
change our published SP metadata to include the "shib"  ACS endpoints, and
make sure those changes propagate to all of our customers' IdP's. Once that
is complete, we will transition to using the "shib" endpoints exclusively
(by redirecting to the "shib" URL instead of the "www" url to get to the
Login handler), and once that has been done we are free to change the "www"
DNS to point at the new server without bringing down SSO functionality.

Is this the best way to go about this? Thanks in advance for your help.



--
View this message in context: http://shibboleth.1660669.n2.nabble.com/DNS-changes-affecting-SP-endpoints-tp7611343.html
Sent from the Shibboleth - Users mailing list archive at Nabble.com.


More information about the users mailing list