Metadata Changeover Questions
McKean, Brandon Scott - mckeanbs
mckeanbs at jmu.edu
Wed Jul 22 08:39:14 EDT 2015
Hi Everyone,
I've been looking at adding new SPs to our existing IDP, but also
transitioning away from SAML 1 in favor of SAML 2 as best we can. To
this end, I'm suspecting I could give new SPs a copy of our metadata
that has SAML1 elements removed in order to achieve a transition.
Here's what we have currently:
> <ArtifactResolutionService
> Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding"
> Location="https://itfederation.jmu.edu:8443/idp/profile/SAML1/SOAP/Ar
> tifactResolution" index="1"/>
>
> <ArtifactResolutionService
> Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https:/
> /itfederation.jmu.edu:8443/idp/profile/SAML2/SOAP/ArtifactResolution"
> index="2"/>
>
> <SingleLogoutService
> Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect"
> Location="https://itfederation.jmu.edu/idp/profile/SAML2/Redirect/SLO
> " />
>
> <SingleLogoutService
> Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="
> https://itfederation.jmu.edu/idp/profile/SAML2/POST/SLO" />
>
> <SingleLogoutService
> Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="
> https://itfederation.jmu.edu:8443/idp/profile/SAML2/SOAP/SLO" />
>
>
> <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameI
> DFormat>
> <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid
> -format:transient</NameIDFormat>
>
> <SingleSignOnService
> Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="
> https://itfederation.jmu.edu/shibboleth-idp/SSO"/>
>
> <SingleSignOnService
> Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="
> https://itfederation.jmu.edu/idp/profile/SAML2/POST/SSO"/>
>
> <SingleSignOnService
> Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign"
> Location="https://itfederation.jmu.edu/idp/profile/SAML2/POST
> -SimpleSign/SSO"/>
>
> <SingleSignOnService
> Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect"
> Location="
> https://itfederation.jmu.edu/idp/profile/SAML2/Redirect/SSO"/>
And here's what I'm thinking we could do:
> <ArtifactResolutionService
> Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https:/
> /itfederation.jmu.edu:8443/idp/profile/SAML2/SOAP/ArtifactResolution"
> index="2"/>
>
> <SingleLogoutService
> Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect"
> Location="https://itfederation.jmu.edu/idp/profile/SAML2/Redirect/SLO
> " />
>
> <SingleLogoutService
> Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="
> https://itfederation.jmu.edu/idp/profile/SAML2/POST/SLO" />
>
> <SingleLogoutService
> Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="
> https://itfederation.jmu.edu:8443/idp/profile/SAML2/SOAP/SLO" />
>
>
> <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid
> -format:transient</NameIDFormat>
>
> <SingleSignOnService
> Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="
> https://itfederation.jmu.edu/idp/profile/SAML2/POST/SSO"/>
>
> <SingleSignOnService
> Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign"
> Location="https://itfederation.jmu.edu/idp/profile/SAML2/POST
> -SimpleSign/SSO"/>
>
> <SingleSignOnService
> Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect"
> Location="
> https://itfederation.jmu.edu/idp/profile/SAML2/Redirect/SSO"/>
Then change:
> <AttributeAuthorityDescriptor
> protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol
> urn:oasis:names:tc:SAML:2.0:protocol">
to something like:
> <AttributeAuthorityDescriptor
> protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
And lastly change from this:
> <AttributeService
> Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding"
> Location="https://itfederation.jmu.edu:8443/shibboleth-idp/AA"/>
>
> <AttributeService
> Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https:/
> /itfederation.jmu.edu:8443/idp/profile/SAML2/SOAP/AttributeQuery"/>
> ;
>
>
> <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameI
> DFormat>
> <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid
> -format:transient</NameIDFormat>
To:
>
>
> <AttributeService
> Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https:/
> /itfederation.jmu.edu:8443/idp/profile/SAML2/SOAP/AttributeQuery"/>;
>
> <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid
> -format:transient</NameIDFormat>
Am I on the right track with this? What I'd want to do is supply the
modified metadata to new SPs so that we have one less thing to worry
about transitioning, and supply it to InCommon so that we could, in
theory at least, have a fairly seamless transition since the IDP still
technically supports SAML1, but would only be advertising SAML2 in
metadata.
Thanks for any tips I can get on this.
Regards,
--
Brandon McKean
IT / Systems
Linux Administrator
(540)568-4235
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20150722/596dce70/attachment-0001.html>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/x-pkcs7-signature
Size: 5673 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/users/attachments/20150722/596dce70/attachment-0001.bin>
More information about the users
mailing list