Our clustering solution for IdP v3

Tom Scavo trscavo at gmail.com
Sun Feb 28 18:16:14 EST 2016


On Sun, Feb 28, 2016 at 5:44 PM, Julian Williams
<julian.williams at it.ox.ac.uk> wrote:
>
> Do we need persistent storage?
>
> We had been thinking until relatively recently that we would have to use
> a PostgreSQL backend (our favoured rdbms here) to store the transientid
> necessary for supporting back-channel connections across multiple nodes.

No, I don't think that's true. Even back in the good old SAML1 days,
the Shibboleth transient name ID included an embedded user identifier,
which was all nicely encrypted into the name ID so that the Attribute
Authority could determine the user by simply decrypting the name ID
that it had encrypted in the first place.

Tom


More information about the users mailing list