metadata-support - Re: [Metadata-Support] Updating IDP Servers in a Pool

Subject: InCommon metadata support

Re: [Metadata-Support] Updating IDP Servers in a Pool

  From: "Cantor, Scott" <>
  • To: "" <>
  • Subject: Re: [Metadata-Support] Updating IDP Servers in a Pool
  Date: Wed, 4 Jan 2017 17:28:18 +0000
On 1/4/17, 11:33 AM,
on behalf of Ryan Bradshaw"
on behalf of

> We have 2 Shibboleth IDP servers behind an F5. We have taken one out to
> upgrade to V3. We can’t have them both in
> the pool as we use Canvas and they require the server cert info.

SPs require your SAML signing certificate, which can and indeed really MUST
not change across upgrades. There are just a whole range of mistakes you have
to have made to be in a situation like this. Stop, and rethink it.

You should not change servers one at a time. Rather, you can simply use the
F5 to switch server pools, or you can make the switch on each server itself
if you put V3 on the same boxes with V2, in which case you may have a bit of
downtime switching between them if you need to fall back.

You need to test the important services ahead of time to ensure no breakage,
which is simple with SAML 2 SPs using the POST binding (the vast majority).

You *cannot* count on any given timeline for metadata update at any relying
party outside of about a day. There's certainly no scheduled time you can
just change. Metadata doesn't work for instantaneous change. It relies on
careful considered changes that occur in a way that never breaks existing RPs
while the changed metadata propagates.

-- Scott

