Skip to content
This repository has been archived by the owner on Apr 26, 2024. It is now read-only.

Commit

Permalink
Add additional SAML2 upgrade notes (#9550)
Browse files Browse the repository at this point in the history
  • Loading branch information
benbz committed Mar 5, 2021
1 parent 8a4b373 commit e5da770
Show file tree
Hide file tree
Showing 2 changed files with 8 additions and 0 deletions.
7 changes: 7 additions & 0 deletions UPGRADE.rst
Original file line number Diff line number Diff line change
Expand Up @@ -124,6 +124,13 @@ This version changes the URI used for callbacks from OAuth2 and SAML2 identity p
need to add ``[synapse public baseurl]/_synapse/client/saml2/authn_response`` as a permitted
"ACS location" (also known as "allowed callback URLs") at the identity provider.

The "Issuer" in the "AuthnRequest" to the SAML2 identity provider is also updated to
``[synapse public baseurl]/_synapse/client/saml2/metadata.xml``. If your SAML2 identity
provider uses this property to validate or otherwise identify Synapse, its configuration
will need to be updated to use the new URL. Alternatively you could create a new, separate
"EntityDescriptor" in your SAML2 identity provider with the new URLs and leave the URLs in
the existing "EntityDescriptor" as they were.

Changes to HTML templates
-------------------------

Expand Down
1 change: 1 addition & 0 deletions changelog.d/9550.doc
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
Improve the SAML2 upgrade notes for 1.27.0.

0 comments on commit e5da770

Please sign in to comment.