On Thu, Jul 5, 2012 at 4:42 PM, Tom Scavo <span dir="ltr">&lt;<a href="mailto:trscavo@gmail.com" target="_blank">trscavo@gmail.com</a>&gt;</span> wrote:<br><div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">

<div>On Thu, Jul 5, 2012 at 7:11 PM, Eric Goodman &lt;<a href="mailto:ericg@ucsc.edu" target="_blank">ericg@ucsc.edu</a>&gt; wrote:<br>
&gt;<br>
&gt; We are running IdP 2.x, and we have been publishing SAML2 endpoints to<br>
&gt; several non-InCommon SPs.<br>
<br>
</div>What bindings do you support? Is HTTP-Redirect one of them?<br></blockquote><div><br></div><div>In the SAML2, yes. Not in the current InCommon data. </div><div><br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">


<div>&gt; However, the metadata we currently publish through<br>
&gt; InCommon is all SAML1. We would like to add our SAML2 endpoints into our<br>
&gt; InCommon metadata.<br>
<br>
</div>That would be great :-)<br>
<div><br>
&gt; My question for the group is: are there any gotchas with doing this? After<br>
&gt; looking through the troubleshooting pages on the wiki, it seems like the<br>
&gt; most common mistake we could make is failing to update all of our relying<br>
&gt; party configs to support SAML2 before the SAML2 endpoints are published, but<br>
&gt; we&#39;re wondering if there are any other gotchas to look for on the IdP or SP<br>
&gt; before making the change.<br>
<br>
</div>Since you&#39;re already interoperating with a select group of SAML2 SPs,<br>
I&#39;m not sure what you&#39;re asking. Seems like all the hard work has<br>
already been done.<br></blockquote><div><br></div><div>I&#39;m really just wondering if adding in the SAML2 can cause any confusion for an SP that was using SAML1 previously. Most of our SAML2 SPs are configured in our relying party to only have SAML2 support (not both SAML1 and SAML2), so I thought there might be a non-obvious way we could cause some sort of confusion between existing SPs and IdPs when we update the InCommon Metadata. And I figure there must be dozens of campuses that have already made this change, so they would be able to tell us if there&#39;s something to be wary of.</div>
<div><br></div><div>--- Eric</div></div>