[IdP 3] Clustering and Backchannel

Peter Schober peter.schober at univie.ac.at
Fri Apr 7 09:57:07 EDT 2017


* Cantor, Scott <cantor.2 at osu.edu> [2017-04-07 15:41]:
> On 4/7/17, 3:54 AM, "users on behalf of Krinetzki, Stephan" <users-bounces at shibboleth.net on behalf of Krinetzki at itc.rwth-aachen.de> wrote:
> 
> > Is this an issue with our backchannel configuration? Or maybe with
> > the SSL/TLS termination at the loadbalancer?
> 
> It's a "the IdP can't authenticate the SP" issue. Shibboleth SPs
> default to client TLS or in the case of very new 2.6 SPs they're
> smart enough to trigger signing if the destination is a SOAP URL on
> port 443. How you want to handle it and what your requirements for
> interoperability are dictate what you have to do, but you almost
> certainly can't do client TLS if you're proxying from a load
> balancer, which means you're talking zero interop with any older SPs
> if they don't turn on signing.
> 
> You need to consider your requirements, why you're using the back
> channel and for whom, to craft a deployment strategy around it.

So configuring the loadbalancer to pass through traffic to the
backchannel port unmolestet should do, and keep interop with older
SAML SPs?
-peter


More information about the users mailing list