Reason behind comment in Metadata

Eric Goodman Eric.Goodman at ucop.edu
Wed Oct 22 17:02:11 EDT 2014


Really, you have to publish the new key(s) long enough for all your SPs to consume it (via updated metadata) before you can pull the old key(s) from your IdP's configuration.

I don't know that there's any formal recommendation on this. If SPs are all consuming metadata through a metadata provider like InCommon, then a good rule of thumb would seem to be at least for the longest validity period the metadata supports -- that is, for InCommon metadata you'd probably want to leave both in place until after the "validUntil" date of the last published metadata that did NOT have the new keys, since in theory they will all have consumed the new metadata by then.

If the SPs are getting their metadata via other channels, the approach is still the same (long enough you're "guaranteed" that the SPs have the new metadata), but the actual amount of time would be derived from whatever that process is.
 
--- Eric

-----Original Message-----
From: dev-bounces at shibboleth.net [mailto:dev-bounces at shibboleth.net] On Behalf Of Dan McLaughlin
Sent: Wednesday, October 22, 2014 1:41 PM
To: Shib Dev
Subject: Re: Reason behind comment in Metadata

Is there a recommended period of time (best practice) for key rollover for an SP or IDP?

--

Thanks,

Dan McLaughlin
Technology Consortium, LLC
dmclaughlin at tech-consortium.com
mobile: 512.633.8086
http://www.tech-consortium.com

NOTICE: This e-mail message and all attachments transmitted with it are for the sole use of the intended recipient(s) and may contain confidential and privileged information. Any unauthorized review, use, disclosure or distribution is strictly prohibited. The contents of this e-mail are confidential and may be subject to work product privileges. If you are not the intended recipient, please contact the sender by reply e-mail and destroy all copies of the original message.
--
To unsubscribe from this list send an email to dev-unsubscribe at shibboleth.net


More information about the dev mailing list