Our clustering solution for IdP v3
Tom Scavo
trscavo at gmail.com
Sun Feb 28 18:16:14 EST 2016
On Sun, Feb 28, 2016 at 5:44 PM, Julian Williams
<julian.williams at it.ox.ac.uk> wrote:
>
> Do we need persistent storage?
>
> We had been thinking until relatively recently that we would have to use
> a PostgreSQL backend (our favoured rdbms here) to store the transientid
> necessary for supporting back-channel connections across multiple nodes.
No, I don't think that's true. Even back in the good old SAML1 days,
the Shibboleth transient name ID included an embedded user identifier,
which was all nicely encrypted into the name ID so that the Attribute
Authority could determine the user by simply decrypting the name ID
that it had encrypted in the first place.
Tom
More information about the users
mailing list