[IdP 3] Clustering and Backchannel

Krinetzki, Stephan Krinetzki at itc.rwth-aachen.de
Mon Apr 10 02:52:01 EDT 2017


>> So configuring the loadbalancer to pass through traffic to the 
>> backchannel port unmolestet should do, and keep interop with older SAML
SPs?

>Generally, although that's not always possible with some load balancers
(not that it's physically a problem, it's just not how the organization
might be using it or be >prepared to configure it).

Yes, with the BIG-IP F5 it should be possible to route all traffic direct to
the nodes without interruption on the load balancer.

>The "best" advice going forward is to urge people to run current SPs, start
putting the SOAP traffic on 443, and hopefully move things over to signed
messages, but >the older SPs won't sign unless they're told to, regardless
of the port.

That's sound good. So i only change my IdP metadata, copy the settings from
the :8443 port to the :443 and I'm done, right? The SP which uses the
backchannel is an 2.6 SP and under my control, so I can adjust the settings
here, regarding signed attribute queries and artifact resolution.

-
Stephan
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 5849 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/users/attachments/20170410/71638128/attachment-0001.p7s>


More information about the users mailing list