SAML2 artifact and IdP clustering
Cantor, Scott
cantor.2 at osu.edu
Wed Feb 13 09:02:30 EST 2019
> "SAML 2.0 artifact use is not supported by default if more than one node is
> deployed, but it is possible to make that feature work with additional
> configuration (discussion TBD)."
>
> Is there "additional configuration" that will enable SAML 2.0 artifact use that
> does NOT require using a separate relational database or key store?
You need a dedicated path into each node under a unique name (and certificate, or at least a multi-name cert), and then you can register separate indexed endpoints into the metadata. Each node has a property we defined assigning it the index value to use, and that gets embedded into the artifact to direct the requests back to the right node.
Is that enough to go on or do you need a more complete write up?
I never documented it due to the obvious lack of demand.
-- Scott
More information about the users
mailing list