Previous Topic: Synchronize Multiple Key DatabasesNext Topic: Back up an Existing Configuration


Verify That Existing Federated SAML Partnerships Do Not Have the Same Backchannel Username

Verify that no existing partnerships have incoming backchannel usernames (within the same protocol) that are the same before upgrading.

That is, no two SAML 2.0 partnerships can share an incoming backchannel username. Similarly, no two SAML 1.0 partnerships can share an incoming backchannel username. A SAML 1.0 and a SAML 2.0 partnership can share an incoming backchannel username but it is not recommended.

If you do have partnerships of the same protocol that share an incoming backchannel username, do the following steps before you upgrade:

  1. Deactivate one of the partnerships.
  2. Change the backchannel username that is defined in that partnership.
  3. Inform the remote partner of the change.

Reactivate the partnership.