SAML message intended destination endpoint did not match the recipient endpoint

Cantor, Scott cantor.2 at osu.edu
Sun Jul 3 13:15:08 EDT 2016


> - Old IDP v2 system (not an option to upgrade to IDP3)

Why? Just saying that doesn't really mean anything.
 
> - On Go live I wouldn’t be able to communicate with 100 plus vendors to
> update the Entity ID and AuthnRequest URL to point to the new IDP3

Which is why you do not do that. Do not change your entityID, and do not change the server name and endpoints or key.

If you want to change servers, that's absolutely fine (I went from V1 to V2 that way). Test it all out, and then flip the switch in DNS. If this is all SAML 2, or mostly, then you can test everything ahead of time very easily with a simple /etc/hosts change on your client.

> - Has anyone been in a similar situation and could advise if my solution is
> viable

It is not the right solution.

-- Scott



More information about the users mailing list