[IdP 3] Clustering and Backchannel
Peter Schober
peter.schober at univie.ac.at
Fri Apr 7 09:57:07 EDT 2017
* Cantor, Scott <cantor.2 at osu.edu> [2017-04-07 15:41]:
> On 4/7/17, 3:54 AM, "users on behalf of Krinetzki, Stephan" <users-bounces at shibboleth.net on behalf of Krinetzki at itc.rwth-aachen.de> wrote:
>
> > Is this an issue with our backchannel configuration? Or maybe with
> > the SSL/TLS termination at the loadbalancer?
>
> It's a "the IdP can't authenticate the SP" issue. Shibboleth SPs
> default to client TLS or in the case of very new 2.6 SPs they're
> smart enough to trigger signing if the destination is a SOAP URL on
> port 443. How you want to handle it and what your requirements for
> interoperability are dictate what you have to do, but you almost
> certainly can't do client TLS if you're proxying from a load
> balancer, which means you're talking zero interop with any older SPs
> if they don't turn on signing.
>
> You need to consider your requirements, why you're using the back
> channel and for whom, to craft a deployment strategy around it.
So configuring the loadbalancer to pass through traffic to the
backchannel port unmolestet should do, and keep interop with older
SAML SPs?
-peter
More information about the users
mailing list