rpm-update shibboleth from version 2 to version 3
William Chan
wchan999 at gmail.com
Thu Jan 31 19:29:15 EST 2019
I did carefully renamed shibboleth2.xml.rpmnew to shibboleth2.xml .
Carefully modified <ApplicationDefaults .. >, <SSO ..>
and <MetadataProvider ..> appropriately.
On Thu, Jan 31, 2019 at 4:06 PM Cantor, Scott <cantor.2 at osu.edu> wrote:
> You can't possibly get that result unless the original installation was
> untouched and never used, in which case the package should have just been
> removed first. If shibboleth2.xml was unmodified (which is impossible for a
> functioning SP doing any real work), then the upgrade would probably
> overwrite that file with the new one but wouldn't generate the new
> keypairs, and it would be out of sync. That's conceivable but was not
> something anticipated.
>
> In any real upgrade, the modified shibboleth2.xml would be untouched (it
> would create shibboleth2.xml.rpmnew), and still referencing the old single
> keypair, and you wouldn't get those messages.
>
> And no, it's not a working system. It would fail to decrypt assertions and
> nobody could login, outside of IdPs not encrypting their assertions.
>
> -- Scott
>
>
> --
> For Consortium Member technical support, see
> https://wiki.shibboleth.net/confluence/x/coFAAg
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20190131/7e19f1ff/attachment.html>
More information about the users
mailing list