SAML2 artifact and IdP clustering

Scott Koranda skoranda at gmail.com
Wed Feb 13 09:11:05 EST 2019


> > "SAML 2.0 artifact use is not supported by default if more than one node is
> > deployed, but it is possible to make that feature work with additional
> > configuration (discussion TBD)."
> > 
> > Is there "additional configuration" that will enable SAML 2.0 artifact use that
> > does NOT require using a separate relational database or key store?
> 
> You need a dedicated path into each node under a unique name (and certificate, or at least a multi-name cert), and then you can register separate indexed endpoints into the metadata. Each node has a property we defined assigning it the index value to use, and that gets embedded into the artifact to direct the requests back to the right node.
> 
> Is that enough to go on or do you need a more complete write up?

That is enough. Thank you, I understand.

Thanks,

Scott K


More information about the users mailing list