Sharing SP Metadata amongst multiple SPs

Cantor, Scott cantor.2 at osu.edu
Sat Nov 7 14:14:40 EST 2015


On 11/7/15, 2:08 PM, "users on behalf of Phil Lello" <users-bounces at shibboleth.net on behalf of phil at dunlop-lello.uk> wrote:


>
>Soapbox is fine with me; there were two scenarios I had in mind, rapid deployment of production environments (where I'll agree it's at best sub-optimal), and development environments where it's desirable to spin up n-m instances that should be identical from an integration perspective.

Dev's a bit of a different matter. I generally register (server) development systems under the same entityID and key as production, just adding the endpoints. If they have dev and QA I'll usually suggest that merge QA and prod, but leave dev separate.

> Whilst I agree the avoided work isn't much in principal, my experience is that application development teams are generally separate from the shibboleth team (who are generally under-resourced), which inevitably leads to long delays.

When you're talking about "inside the firewall" and use in an enterprise situation, most of what I was talking about goes out the window. Then it's more a matter of local norms and workflow. And if you control the IdP, that goes hand in hand, since you can choose to disable endpoint checking for those SPs.

That's why I was saying it matters a lot exactly how much control you have.

-- Scott



More information about the users mailing list