Hello Folks,

 

We are in our planning process of upgrading from our current r12.52 to r12.8 and we have a few questions specifically regarding the “hopefully” improved and changes on the r12.8 Federation Partnership model.

 

Two years ago we upgraded from r12.0 to r12.52 and were introduced to the new Federation Partnership model for creating Federation SSO configurations.  Right away we noticed a major show stopper which CA acknowledge as a bug.  This show stopper issue with the r12.52 Federation Partnership is the missing “federation application URL” field from within the Admin UI when utilizing the custom Assertion Generator Plugin.

 

With the Legacy Federation you have the option to specify the “Application URL” to redirect the browser to an application where we would collect additional user attribute/parameters which will then be passed back to the custom assertion generator plugin (AGP).  With the Partnership Federation we don’t seem to have that option within the Admin UI when creating federation partnership configuration (please see attached images).

 

The second question that we want to know is, with the R12.8 Partnership Federation model, do we still need to “Deactivate” the partnership in order to modify or make configuration changes to that partnership?  At times we are required to make configuration changes to an existing SAML service provider in our Legacy Federation configuration, but this change does not require any downtime.  With the Partnership Federation, it requires you to “Deactivate” a particular federation partnership in order to make any changes to it, this will cause downtime.

 

Also, the r12.52 Admin UI seemed quite slow in performance when navigating through the Partnership Federation, has this performance changed with later releases?

 

Much thanks in advance!

 

Duc,


Source: New feed
{pubDate}

Leave a Reply

Your email address will not be published. Required fields are marked *