Shibboleth Identity Provider Deployment

Deployment Guides
Shibboleth IdP 4.x
Shibboleth IdP 3.x
Installation and Configuration
For sites with IdP v2 deployments which are preparing for an upgrade to v3, the page on Considerations regarding Shibboleth IdPv3 in the Context of SWITCHaai is suggested reading. It documents the decisions and recommendations SWITCH has taken prior to writing the installation guide.
User Consent Configuration
Learn how you can configure what regarding user consent for Shibboleth IdPv3:
Load Balancing / High Availability
If you are interested in a clustered setup of your IdP, you may have a look at our informational page about clustering:
Shibboleth IdP 2.4 (legacy)
Installation and Configuration
Migration and Upgrades
- Upgrade Identity Provider from 3.x to latest version of 3
- Upgrade Identity Provider from 2.0/2.1/2.2/2.3 to 2.4
- Upgrade Identity Provider from 2.4.x to 2.4.4
Load Balancing / High Availability
Currently, we do not recommend to use Terracotta software as it will no longer be supported in IdP 3.
Also refer to the Shibboleth Wiki on
https://wiki.shibboleth.net/confluence/display/SHIB2/IdPClusterIntro.
For further questions, please don't hesitate to contact aai@switch.ch.
Interfederation Support
The following guide explains how an Identity Provider can be configured to allow its users to access AAI resources in other federations outside of Switzerland. For deployment instructions, have a look at the interfederation deployment guide.
Certificate Roll-Over
- Identity Provider Certificate Rollover Guide (replacing an old with a new certificate)
- Acceptable Certificates
Attributes about Users that need to be supported
Every SWITCHaai Home Organization has to be able to provide a certain set of user attributes to resources. See the AAI Attributes page for details.
Design Templates
- Design guidelines for login page
Best Current Practices for SWITCHaai service operations
Best current practices for operating a SWITCHaai Identity Provider
Further Documentation
- Shibboleth 2 IdP Documentation (Shibboleth Wiki)
- Identity Provider Common Errors (Shibboleth Wiki)
- Shibboleth mailing lists