Transitioning from an old to new IdP instance
coupons at sccoast.net
coupons at sccoast.net
Wed May 14 14:47:35 UTC 2025
Sorry. My wording may be distorted somewhat.
I meant to say I did copy the old established keys over to the new
server so they would match with our existing IdP metadata that our SP's
are currently using.
It's working fine on dev Idp but I just wanted to double check since
prod IdP obviously see's more activity and exposure.
Eventually migrate to new certs/keys but first wanted to get the new IdP
version up and running.
- Dave
On 5/14/25 10:10 AM, Peter Schober via users wrote:
> coupons at sccoast.net <coupons at sccoast.net> [2025-05-14 14:16 CEST]:
>> What I actually did was a fresh install of Shib 5.x on our dev
>> server got it running good and working with all SP's, no errors.
> [...]
>> Finally I was going to copy over the 'credentials' -
>> signing/encryption certs/keys from our old Shib 3.x to the new Shib
>> 5.x and hoping that would be good to go.
> How could you have determined that it was
> "working with all SP's, no errors"
> when the IDP didn't even have the established keys?
> I.e., you cannot possibly have tested this with real SPs -- or they're
> all fundamentally broken by letting you in with messages signed with
> completely different keys.
>
>> These steps seem like they would work ok.
> Unless/Until they don't. E.g. when the new software uses new defaults
> for encryption algorithms that some of your SPs are not compatible
> with.
>
> -peter
More information about the users
mailing list