[IdP 3] Clustering and Backchannel

Cantor, Scott cantor.2 at osu.edu
Fri Apr 7 09:41:08 EDT 2017


On 4/7/17, 3:54 AM, "users on behalf of Krinetzki, Stephan" <users-bounces at shibboleth.net on behalf of Krinetzki at itc.rwth-aachen.de> wrote:

> Is this an issue with our backchannel configuration? Or maybe with the SSL/TLS termination at the loadbalancer?

It's a "the IdP can't authenticate the SP" issue. Shibboleth SPs default to client TLS or in the case of very new 2.6 SPs they're smart enough to trigger signing if the destination is a SOAP URL on port 443. How you want to handle it and what your requirements for interoperability are dictate what you have to do, but you almost certainly can't do client TLS if you're proxying from a load balancer, which means you're talking zero interop with any older SPs if they don't turn on signing.

You need to consider your requirements, why you're using the back channel and for whom, to craft a deployment strategy around it.

-- Scott




More information about the users mailing list