How-to build a custom federation
Cantor, Scott
cantor.2 at osu.edu
Thu Sep 17 09:42:28 EDT 2015
On 9/17/15, 5:20 AM, "users on behalf of romain.dauby at orange.com" <users-bounces at shibboleth.net on behalf of romain.dauby at orange.com> wrote:
>We needed an IDPv3 for technical issues in a new product. And we are going to migrate others SP to this new IDPv3 without service interruption. But we have lots of SPs, it'll take a long time (we plan about 6 months or more).
You don't migrate SPs to an IdP, that's the point. Upgrading an IdP doesn't involve the SPs, it just involves you. Once you involve the SPs, you've turned a weeks long project into years.
>So it's a comfort if users don't need to click on something to login in all SPs regardless the IDP.
If you want that, then you need an authentication mechanism that provides SSO across the IdPs. That's not a Shibboleth feature, that's a separate issue.
-- Scott
More information about the users
mailing list