Overwriting policy in upgrading

Cantor, Scott cantor.2 at osu.edu
Wed Jan 4 09:49:19 EST 2017


On 1/4/17, 5:47 AM, "users on behalf of Takeshi NISHIMURA" <users-bounces at shibboleth.net on behalf of takeshi at nii.ac.jp> wrote:

> New features would be, but some bug fixes and improvements would not, at least for *.vm files.

Almost any vm files in user space have to be modified to be worth using (which means we can't change them or remove them anyway no matter what we script).

>  I wonder whether IDP-986 is effective without overwriting ldap-authn-config.xml.

No, but that is not a bug fix, and if you're using LDAP and not reviewing every setting related to timeouts yourself, I would have to question that. Defaults matter but they don't replace basic practice.

> Except for messages files, three files are removed since 3.1.2. It is confusing if they remain in /opt/shibboleth-idp/views/
> and the last one will prevent future updates of that in system/views/.

The password one was actually a regression, I didn't realize what I was doing when I moved it. I thought it was a new file added for 3.3 because of the interceptor I was working on. It's probably better for it to stay there but for new installs it's unfortunately moved down. The others certainly don't hurt anything being there.

The fact is, we're going to have to do a 4.0, probably this year or next. When we do, all this is moot because we'll have the freedom to make changes by requiring some intervention or scripting the installer to do certain kinds of cleanup or detect these sorts of legacy files. Major transitions are the best time to focus on cleanup and consistency.

-- Scott
 



More information about the users mailing list