Shib 3.x & alternate credentials
Dave Bartholomew
Dave.Bartholomew at csueastbay.edu
Wed Oct 28 12:50:44 EDT 2015
> Whatever you're doing here, if use of production credentials is an
option why not instead make a clone the whole prod IDP machine, give that
second machine a different IP address, and modify your local (i.e., on
your workstation or PC) resolver[1] to point the DNS name of the prod host
to IP address of the the new/cloned IDP.
Yes, I'm planning to do something similar with production, but it won't be
a clone of the whole machine as I'm moving from Linux to Windows in the
process. I'm hoping to use the production credentials and entityID and
basically make the switch via a DNS change. Since both IdPs would still be
running, I wouldn't expect much disruption of a relatively lightly-used
IdP with only a small number of "in betweeners" having a problem. Also, I
would expect to easily revert to Shib 2.x with another DNS change. Am I
missing anything, or does this sound workable?
While on the subject of credentials, what's your take on the desirability
of using the shiny new SHA256 self-signed credentials vs. the 2.x SHA1
pair that I'd be bringing over?
Thanks for your input.
--Dave
More information about the users
mailing list