Some SP Hub instability underway

Scott Cantor scott at restingparrotsoftware.com
Wed Jul 29 12:15:33 UTC 2026


> I hope to get this stabilized and documented this week, at least on the SAML side.

I believe it's back to stable this morning and I just published new Maven builds. I updated much of the key/certificate documentation yesterday as well.

I *think* it nominally would work without updating any older testing configurations, but I didn't test it or care much about that. The change going forward is that the SAML plugin will now generate default keypairs for signing and encryption if they're absent, and the names of the files inside the properties used for them have changed slightly.

Per the docs, this eliminates the manual import of the old saml-credentials.xml file into agents.xml and it's now unneeded entirely as the default keypairs are installed internally.

The docs on the new credential service exist [1] but are sparse because there aren't yet any actual new resolvers built to support more advanced key and certificate access or selection. This change is just the first step to get the service in place and used to get at them and to automate the OOB install.

Phil is working on the parallel changes for OIDC but that's more complex because it's usually in need of client secrets so the config on that is TBD.

I'm going to park this while I get the ECP support knocked out, but before we ship we'll have a viable story for doing per-Agent (and/or per-IdP) key management in the Hub that is at least usable if not fancy.

-- Scott

[1] https://shibboleth.atlassian.net/wiki/spaces/sphub1/pages/5539168277/CredentialResolverService


More information about the dev mailing list