Upgrading IDP by Changing SingleSignOnService Locations and Certificates at the Same Time

Albert Luo albert.uwin at gmail.com
Tue Dec 19 14:52:34 EST 2017


We have two IDPs, IDP A and IDP B.

IDP A is an older version of Shibboleth IDP. IDP A's metadata is
currently in the federation aggregates. We plan to replace IDP A's
metadata with IDP B's  metadata and retire IDP A from service.

IDP A and IDP B have  the same entityID, same organization name.

IDP A and IDP B metadata have different sets of signing/encryption
certificates, and different sets of SingleSignOnService Locations.

IDP A and IDP B are configured with same set of MetadataProvider.
Attribute source, attribute resolver, attribute release policy is
configured to be the same. Both will be online during the migration
process.

Our plan is to provide IDP B's metadata to the federation to replace
IDP A's metadata. The IDP B's metadata will eventually propagate to
the SPs. When a SP pick up the  IDP B's metadata, the SP will start
redirecting logins to the IDP B's SingleSignOnService Locations, and
will use IDP B's certificate for SAML exchanges.

In this scenario,  we will not need certificate roll over. Assuming
IDP B is configured correctly, SPs will switch to IDP B peacefully.

Is my understanding of the migration process correct? Do you see any
problem with this plan? Has anybody migrate/upgrade IDP this way?
Thank you  very much for sharing your experience.


More information about the users mailing list