rpm-update shibboleth from version 2 to version 3
Cantor, Scott
cantor.2 at osu.edu
Thu Jan 31 19:06:20 EST 2019
You can't possibly get that result unless the original installation was untouched and never used, in which case the package should have just been removed first. If shibboleth2.xml was unmodified (which is impossible for a functioning SP doing any real work), then the upgrade would probably overwrite that file with the new one but wouldn't generate the new keypairs, and it would be out of sync. That's conceivable but was not something anticipated.
In any real upgrade, the modified shibboleth2.xml would be untouched (it would create shibboleth2.xml.rpmnew), and still referencing the old single keypair, and you wouldn't get those messages.
And no, it's not a working system. It would fail to decrypt assertions and nobody could login, outside of IdPs not encrypting their assertions.
-- Scott
More information about the users
mailing list