Shibboleth SP migration plan

MikeWho who at me.com
Thu Jan 22 13:06:09 EST 2015


Cantor, Scott E. wrote
>> We're migrating several instances of Shibboleth SP and their respective
>> sites to a new data centre, and the following is our plan for migrating
>> the
>> SPs. We're really hoping to avoid any re-integration with the IdPs - some
>> clients' IdPs only do quarterly updates, plus if they see this as a new
>> integration there could be a non-trivial cost involved.
> 
> I hope they're under no illusions that that's a secure way to operate.

To clarify - they perform maintenance/security updates as required. But they
only allow SP metadata & configuration updates during quarterly windows. I
don't know if there are security repercussions from that - if an SP needs to
urgently push metadata with an updated cert I presume. There certainly are
convenience / scheduling / budgetary / stress repercussions..

> For testing, I'm hoping I can just edit a local hosts file on a test
> machine, to point the site/SP domain names to the new datacentre
> addresses.
> >From what I've read, the IdP doesn't normally communicate directly with
> the SP (is that for Artefact binding? - which we don't use), so hopefully
> that
> let's us test the new setup in advance of the DNS changeover.

Yes, it does. What Peter was talking about is if you move an IdP. The only
direct connection from IdP to SP is artifact binding or backchannel logout,
neither of which any Shibboleth IDP version supports at this time.


Thanks for the clarification. As stated in the other post we currently
neither use artifact binding nor any back-channel comms so I think we're
good.

Mike.



--
View this message in context: http://shibboleth.1660669.n2.nabble.com/Shibboleth-SP-migration-plan-tp7611070p7611075.html
Sent from the Shibboleth - Users mailing list archive at Nabble.com.


More information about the users mailing list