List of Shib IdP V3 features?
Cantor, Scott
cantor.2 at osu.edu
Tue Jun 7 13:38:28 EDT 2016
> * Tom Scavo <trscavo at internet2.edu> [2016-06-07 18:56]:
> > I'm involved in planning for a communications campaign to Shibboleth
> > IdP deployers in the InCommon Federation. Beyond the release notes in
> > the wiki, is there a published list of IdP V3 new features?
>
> I think summarizing what you consider the main points from the release
> notes is the best you can do.
I've done slides but nothing in the wiki.
My usual response to this is "it's supported and not dead code walking running on an outdated Spring library likely to fail completely within a year or two". It is the only version suitable for use at present, so what it can or can't do isn't all that germane except with regard to upgrading vs. running something else.
My focus was generally more on what the upgrade proposition is, meaning what has to change and what doesn't have to. Usually the selling point there is to minimize what has to change, which is counter to discussing a lot of new features. I kind of downplayed that deliberately.
The usual highlights are:
- vastly better upgrade and patching process
- cleaned up storage options and out of the box HA without additional software
- the consent feature
- expanded authentication options with more coming
- modernized defaults, e.g. SHA-2
- much more configuration flexibility in dealing with advanced use cases, e.g. per-RP behavior for basically every detail of the system
- much easier to extend in most areas, a lot via scripting
- on-demand reload of configuration/metadata
- single logout (barely works yet, but it's there)
- CAS support
Probably overlooking some things.
-- Scott
More information about the users
mailing list