Transitioning IdPs

Cantor, Scott cantor.2 at osu.edu
Wed Feb 13 14:36:17 EST 2019


> when a
> browser that has a session with one version of the IdP tries to negotiate a new
> session that only knows about the other IdP, what would happen? (rhetorical
> question, BTW, unless the answer is "nothing bad')

Unless just not having SSO and logging in again is "bad", I would imagine nothing bad is a pretty close approximation. Running that way for weeks, no, but for a short transition of DNS I would think all the other options are much worse.

That's not to say you can reasonably expect to pull off such a quick transition without breaking everything (I would expect that part to be the much harder proposition), but that's not going to be because of clients transitioning from an old to new address.

The usual problem is that running in parallel like that is a matter of weeks, not days.

-- Scott



More information about the users mailing list