IDP 3 clustering
Hong Ye
hy93 at cornell.edu
Thu Jun 25 16:46:05 EDT 2015
We have to cluster IDP 2.4 before we upgrade to IDP 3.0 in prod. While I’m making changes in IDP 2.4 clustering, I need to know if the same changes are needed in IDP 3.0. IDP3 clustering wiki page doesn’t mention AttributeQuery while IDP 2 does. That’s why my initial questions are about IDP 3. Sorry about the confusion when switching between IDP 3. and 2
Now I understand I don’t need these "Crypto Transient ID Attribute definition” etc in IDP 3 clustering. But I still need them in IDP 2 clustering. Then that question again: Do I need to modify attribute-filter.xml to release cryptoTransientId instead of transientId for IDP 2 clustering?
Thanks for your replies.
Hong
On Jun 25, 2015, at 3:39 PM, Cantor, Scott <cantor.2 at osu.edu<mailto:cantor.2 at osu.edu>> wrote:
That's a V2 thing, not a V3 thing.
We are currently running IDP 2.4.
Then why does the subject line say IDP 3 clustering?
According to Pete Schober's reply earlier,
this has been brought forward to IDPv3. Now I'm confused.
The functionality is there, that doesn't mean you need to apply deprecated settings and options.
I'm not sure I understand what you mean.
I mean, stop doing things. If you upgraded a V2 IdP that was not using the crypto plugins for clustering use, then these settings won't be there and won't be needed. If you're starting from scratch, they're also not needed. So either way, not needed.
Our IDP releases transientid by default.
transientID is no longer an attribute you need to release at all. Any references to it in the resolver are deprecated and no longer needed. They won't hurt anything, but they won't be used either.
I added "Crypto Transient ID Attribute definition" in attribute-
resolver, but if I don't release it in attribute-filter, how does the SP use
cryptoTransientId?
Take a look at the NameID generation documentation in the wiki. With respect to how queries are handled, that's discussed in the NameID consumption documentation.
For transient support, all of this is installed by default now, and has nothing to do with attributes anymore because this is not an attribute at all, it's a NameID type.
-- Scott
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net<mailto:users-unsubscribe at shibboleth.net>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20150625/f554fbb7/attachment.html>
More information about the users
mailing list