rpm-update shibboleth from version 2 to version 3

Cantor, Scott cantor.2 at osu.edu
Thu Jan 31 19:06:20 EST 2019


You can't possibly get that result unless the original installation was untouched and never used, in which case the package should have just been removed first. If shibboleth2.xml was unmodified (which is impossible for a functioning SP doing any real work), then the upgrade would probably overwrite that file with the new one but wouldn't generate the new keypairs, and it would be out of sync. That's conceivable but was not something anticipated.

In any real upgrade, the modified shibboleth2.xml would be untouched (it would create shibboleth2.xml.rpmnew), and still referencing the old single keypair, and you wouldn't get those messages.

And no, it's not a working system. It would fail to decrypt assertions and nobody could login, outside of IdPs not encrypting their assertions.

-- Scott




More information about the users mailing list