Transitioning from an old to new IdP instance

IAM David Bantz dabantz at alaska.edu
Wed May 14 01:24:04 UTC 2025


If you haven't already, read the warnings about this method of "upgrading"
the Shibboleth IdiP:

https://shibboleth.atlassian.net/wiki/spaces/IDP5/pages/3199500925/Upgrading


On Tue, May 13, 2025 at 11:59 AM <coupons at sccoast.net> wrote:

> We're building a new IdP server with Shib. 5x IdP to replace our current
> older Shib. IdP server.
>
> If the 'credentials' folder (cert/keys) from the old server is copied to
> the new server build, all SP providers should be able to communicate
> without any changes, correct?
> No metadata changes with new signing/encryption certs are necessary,
> correct? All the old sign/encrypt certs are still valid and all other
> 'conf' files updated of course.
>
> Just trying to limit downtime by stopping old server instance and starting
> the new instance.
>
> Thanks,
> Dave
>
> --
> For Consortium Member technical support, see
> https://shibboleth.atlassian.net/wiki/x/ZYEpPw
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20250513/fa66e8fd/attachment.htm>


More information about the users mailing list