Cert rollover sanity check
Mike Flynn
shibbolethlynda at yahoo.com
Thu Oct 20 18:08:47 BST 2011
The 3 week propagation was taken from https://spaces.internet2.edu/display/InCCollaborate/Certificate+Migration
Specifically:
Since InCommon participants are strongly encouraged to update their metadata daily, you should wait at least a day for your new metadata to propagate. You may want to wait longer, however.
>>We recommend you wait three (3) weeks for the metadata to propagate, since any given Federation metadata file has an explicit 3-week lifetime.I wanted to err on the side of caution. Other than that my plan looks sound?
________________________________
From: "Cantor, Scott" <cantor.2 at osu.edu>
To: "users at shibboleth.net" <users at shibboleth.net>
Sent: Thursday, October 20, 2011 10:00 AM
Subject: Re: Cert rollover sanity check
On 10/20/11 12:50 PM, "Mike Flynn" <shibbolethlynda at yahoo.com> wrote:
>My cert in InCommon is expired and as such I am looking to update
>it. I probably would never have noticed it was expired had I not tried
>to integrate with Ball State. They are using an AD FS based Idp and it
>balked at the expired cert.
Any IdP other than Shibboleth and probably simpleSAML.php is probably
going to require manual intervention, but it's very likely such IdPs won't
be using your key for anything but encryption anyway, so they could switch
once you install the new key.
>4. Wait 3 weeks for propogation:
Or a day?
-- Scott
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20111020/3d8a280a/attachment-0001.html
More information about the users
mailing list