Bug 56824 - Register SAML schema in domain
Register SAML schema in domain
Status: CLOSED FIXED
Product: UCS
Classification: Unclassified
Component: SAML
UCS 5.0
Other Linux
: P5 normal (vote)
: UCS 5.0-5-errata
Assigned To: Florian Best
Felix Botner
:
Depends on: 56765
Blocks: 56134
  Show dependency treegraph
 
Reported: 2023-11-14 18:27 CET by Florian Best
Modified: 2023-11-21 12:08 CET (History)
1 user (show)

See Also:
What kind of report is it?: ---
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Max CVSS v3 score:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Florian Best univentionstaff 2023-11-14 18:27:50 CET
The LDAP schema for SAML objects are currently hardcoded in the univention-saml-schema package and not reqistered as LDAP extension in the domain.
Purging the package will therefore cause slapd to not start anymore.

For the UCS 5.2 upgrade we need the schema to be registered (e.g. for mixed environments with UCS 5.0).

+++ This bug was initially created as a clone of Bug #56765 +++

SimpleSAMLphp will not be supported in 5.2 anymore, we need to adjust the defaults and remove obsolete code to switch to Keycloak
Comment 1 Florian Best univentionstaff 2023-11-16 17:15:40 CET
The schema is now registered in the joinscript 91univention-saml (which belongs to univention-saml and not univention-saml-schema, but is only installed on DC Primary/Backup where we are allowed to increase the joinscript version during errata updates).

univention-saml.yaml
2d01ebfdf63c | feat(saml): register LDAP schema and UDM modules domainwide in the LDAP

univention-saml (7.0.8-9)
965ec29b6990 | fix(saml): fix remove handling of saml/idpconfig objects in listener
2d01ebfdf63c | feat(saml): register LDAP schema and UDM modules domainwide in the LDAP
Comment 2 Felix Botner univentionstaff 2023-11-16 17:34:14 CET
OK - univention-saml 7.0.8-10
OK - yaml
OK - univention-saml not installed on slave, member
OK - univention-saml join automatically executed on primary and backup
OK - schema and udm stuff is registered
OK - update works (primary then backup, and vice versa or replica first)
OK - update to 5.2