Feature 4975 Testing Feedback - Auto SAML Metadata Download Feature

@jspecht

Today we got notification that IDP cert change season is upon us so it was the first time I had the chance to perform a cert swap to test feature 4975. The following was what was done and the result

  1. Upgrade the target gateway to 8.1.18
  2. Login to the gateway using SAML SSO >> Success
  3. Using the existing SAML IDP connection, perform a test login >> Success
  4. On the IDP side, swap to the new cert which expires in 2023
  5. Perform another test login >> Fail
  6. Update the following settings on the IDP connection:

image

  1. Performed another test login >> Success
  2. Logged out of and then back into the gateway >> success

So at least on the initial test that I have done at one site, as long as the Ignition version is correct and the proper settings are made in the gateway IDP connection (shown in the above photo) when swapping the cert on the IDP provider side, the gateway will automatically recognize and download the new metadata without having to import it manually.

We will have a good deal of work to do this year in order to get everything in place, but from next year we will see real benefits in terms of how much effort is required to make the yearly IDP provider side cert swap.

Thanks,

Nick

4 Likes

Hi Nick -

Thank you for sharing the details of your test results. The test procedure you used and the conclusions you have drawn seem sound to me. I believe you will start seeing a real benefit as well given the scale you have to deal with.