SDSS and Shibboleth 1.3
The release of Shibboleth 1.3 has implications for different categories of SDSS user as follows:
- Users new to Shibboleth
- You will find that the documentation of how to configure Shibboleth to participate in the SDSS federation assumes that you are deploying Shibboleth 1.2. This situation is likely to persist for some time, so you need to make a choice between installing 1.2 and having matching documentation available or installing 1.3 and having to identify where you will need to do something different from what is described here (and what to do). For new users, we would therefore recommend 1.2, but be aware that support from the Shibboleth Core Team, via the shibboleth-users mailing list, is likely to focus increasingly on 1.3.
- Existing SDSS users
- There is no plan to force members to upgrade: 1.2 support will be maintained for a considerable time yet. However, for those who do wish to upgrade, adding to the federation a new 1.3 installation that uses only 1.2 features (e.g., the Browser/POST profile but not the Browser/Artifact profile) requires the same information described in the existing JoinFederation documentation. The URLs conventionally used for 1.3 endpoints are slightly different though:
- e.g., for an IdP, the "HS Location" is now conventionally ".../shibboleth-idp/SSO" instead of ".../shibboleth/HS"; and the "AA Location" is now conventionally ".../shibboleth-idp/AA" instead of ".../shibboleth/AA".
- If you upgrade an existing deployment then you can contact us directly with the new endpoint URLs and we will update the metadata. Similarly, adding 1.3-specific metadata elements is also possible by contacting us directly, though support for such configurations is likely to be limited until everyone learns more about 1.3.
- Sites running Shibboleth 1.3 need to download metadata from http://sdss.ac.uk/fed/sdss-metadata.xml rather than the sdss-sites-12.xml and sdss-trust-12.xml files. We have verified that 1.3 IdPs and 1.3 SPs that use only 1.2 features interoperate successfully with existing Shibboleth 1.2 entities within the SDSS federation.