IdP v3 not releasing attributes to SAML1 SPs
Jeffrey Crawford
jeffreyc at ucsc.edu
Fri Aug 26 14:41:29 EDT 2016
Just an FYI but we had a similar situation, and it turned out to have
nothing to do with the IdP but the updated java offering ciphers that a
very old SAML1 SP could no longer negotiate. I only figured it out because
I got a hold of the SP owner and got logs from them that showed SSL
connections failed to our back port channel.
We had many newer SMAL1 SP's that didn't have the problem though.
Jeffrey E. Crawford
Enterprise Service Team <jeffreyc at ucsc.edu>
Both pilots and IT professionals require training and currency before
charging into clouds!
---------------------------------------
On Thu, Aug 25, 2016 at 1:14 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:
> On 8/25/16, 3:55 PM, "users on behalf of Mark K. Miller" <
> users-bounces at shibboleth.net on behalf of max at psu.edu> wrote:
>
> > > not offering a second
> > > port,
>
> > Is this tomcat and/or apache? Or, is it really an IdP config change?
>
> Jetty (and our NetScaler when I get around to it). I haven't torn any of
> it down yet, I just updated my metadata for the moment.
>
> The last step will be to switch the transient ID strategy back to
> in-memory so they're not 200 characters long with extra AES operations for
> no reason.
>
> -- Scott
>
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160826/d5707675/attachment.html>
More information about the users
mailing list