Upgrading IDP by Changing SingleSignOnService Locations and Certificates at the Same Time
Albert Luo
albert.uwin at gmail.com
Tue Dec 19 14:52:34 EST 2017
We have two IDPs, IDP A and IDP B.
IDP A is an older version of Shibboleth IDP. IDP A's metadata is
currently in the federation aggregates. We plan to replace IDP A's
metadata with IDP B's metadata and retire IDP A from service.
IDP A and IDP B have the same entityID, same organization name.
IDP A and IDP B metadata have different sets of signing/encryption
certificates, and different sets of SingleSignOnService Locations.
IDP A and IDP B are configured with same set of MetadataProvider.
Attribute source, attribute resolver, attribute release policy is
configured to be the same. Both will be online during the migration
process.
Our plan is to provide IDP B's metadata to the federation to replace
IDP A's metadata. The IDP B's metadata will eventually propagate to
the SPs. When a SP pick up the IDP B's metadata, the SP will start
redirecting logins to the IDP B's SingleSignOnService Locations, and
will use IDP B's certificate for SAML exchanges.
In this scenario, we will not need certificate roll over. Assuming
IDP B is configured correctly, SPs will switch to IDP B peacefully.
Is my understanding of the migration process correct? Do you see any
problem with this plan? Has anybody migrate/upgrade IDP this way?
Thank you very much for sharing your experience.
More information about the users
mailing list