[IdP 3] Clustering and Backchannel
Krinetzki, Stephan
Krinetzki at itc.rwth-aachen.de
Mon Apr 10 02:52:01 EDT 2017
>> So configuring the loadbalancer to pass through traffic to the
>> backchannel port unmolestet should do, and keep interop with older SAML
SPs?
>Generally, although that's not always possible with some load balancers
(not that it's physically a problem, it's just not how the organization
might be using it or be >prepared to configure it).
Yes, with the BIG-IP F5 it should be possible to route all traffic direct to
the nodes without interruption on the load balancer.
>The "best" advice going forward is to urge people to run current SPs, start
putting the SOAP traffic on 443, and hopefully move things over to signed
messages, but >the older SPs won't sign unless they're told to, regardless
of the port.
That's sound good. So i only change my IdP metadata, copy the settings from
the :8443 port to the :443 and I'm done, right? The SP which uses the
backchannel is an 2.6 SP and under my control, so I can adjust the settings
here, regarding signed attribute queries and artifact resolution.
-
Stephan
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 5849 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/users/attachments/20170410/71638128/attachment-0001.p7s>
More information about the users
mailing list