Cert rollover sanity check

Cantor, Scott cantor.2 at osu.edu
Thu Oct 20 18:00:01 BST 2011


On 10/20/11 12:50 PM, "Mike Flynn" <shibbolethlynda at yahoo.com> wrote:

>My cert in InCommon is expired and as such I am looking to update
>it.  I probably would never have noticed it was expired had I not tried
>to integrate with Ball State.  They are using an AD FS based Idp and it
>balked at the expired cert.

Any IdP other than Shibboleth and probably simpleSAML.php is probably
going to require manual intervention, but it's very likely such IdPs won't
be using your key for anything but encryption anyway, so they could switch
once you install the new key.

>4. Wait 3 weeks for propogation:

Or a day?

-- Scott



More information about the users mailing list