Shibboleth SP migration plan
Peter Schober
peter.schober at univie.ac.at
Thu Jan 22 12:31:07 EST 2015
* MikeWho <who at me.com> [2015-01-22 17:54]:
> For testing, I'm hoping I can just edit a local hosts file on a test
> machine, to point the site/SP domain names to the new datacentre addresses.
> >From what I've read, the IdP doesn't normally communicate directly with the
> SP (is that for Artefact binding? - which we don't use), so hopefully that
> let's us test the new setup in advance of the DNS changeover.
I only commented on the backchannel before, not on the testing methodology.
Yes, modifying your local resolver is a great way to test both SAML
IDPs and SAML SPs, provided the backchannel can be avoided (it usually
can).
That's even better than having seperate test system with a seperate
hostname and different keys and configuration etc., as you can test with
production IDPs just the same, whereas with a seperate test IDP not
all IDPs would know that or send it attributes.
(Even more so for IDPs: With a seperate test IDP going by another
entityID and endpoint URLs you can't test most production SPs, as they
wouldn't know about the test IDP, or wouldn't have it mapped to the
same customer/contract/institution as your prod one.)
Always assuming the test system (which you access via your manipulated
resolver) has access to and is configured with the prod system keys
and configuration.
Took me far too long to think about doing that.
-peter
More information about the users
mailing list