rpm-update shibboleth from version 2 to version 3
William Chan
wchan999 at gmail.com
Thu Jan 31 20:05:05 EST 2019
Are you saying that, after the rpm update, I should leave the existing
shibboleth2.xml
and shibboleth2.xml.rpmnew alone ?
I recalled that, after the rpm update, I got some error ( I do not recall
what it was now ). That prompted me to look in /etc/shibboleth and realized
there was a shibboleth2.xml.rpmnew, which triggered me to do the
modifications.
On Thu, Jan 31, 2019 at 4:37 PM Cantor, Scott <cantor.2 at osu.edu> wrote:
> On 1/31/19, 7:29 PM, "users on behalf of William Chan" <
> users-bounces at shibboleth.net on behalf of wchan999 at gmail.com> wrote:
>
> > I did carefully renamed shibboleth2.xml.rpmnew to shibboleth2.xml .
> Carefully modified <ApplicationDefaults .. >,
> > <SSO ..> and <MetadataProvider ..> appropriately.
>
> If you deliberately do that, you'd break it, pretty transparently since
> it's telling you exactly what's wrong. That's not how upgrades are done (or
> documented).
>
> -- Scott
>
>
>
>
>
>
>
>
>
>
> On Thu, Jan 31, 2019 at 4:06 PM Cantor, Scott <cantor.2 at osu.edu> wrote:
>
>
> You can't possibly get that result unless the original installation was
> untouched and never used, in which case the package should have just been
> removed first. If shibboleth2.xml was unmodified (which is impossible for a
> functioning SP doing any real work),
> then the upgrade would probably overwrite that file with the new one but
> wouldn't generate the new keypairs, and it would be out of sync. That's
> conceivable but was not something anticipated.
>
> In any real upgrade, the modified shibboleth2.xml would be untouched (it
> would create shibboleth2.xml.rpmnew), and still referencing the old single
> keypair, and you wouldn't get those messages.
>
> And no, it's not a working system. It would fail to decrypt assertions and
> nobody could login, outside of IdPs not encrypting their assertions.
>
> -- Scott
>
>
> --
> For Consortium Member technical support, see
> https://wiki.shibboleth.net/confluence/x/coFAAg <
> https://wiki.shibboleth.net/confluence/x/coFAAg>
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net <mailto:users-unsubscribe at shibboleth.net>
>
>
>
>
> --
> For Consortium Member technical support, see
> https://wiki.shibboleth.net/confluence/x/coFAAg
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20190131/3b15324a/attachment.html>
More information about the users
mailing list