SP Key Rollover with IdP encryptAssertions="conditional"

Leung, Warren wleung at it.ucla.edu
Thu Sep 22 16:50:33 BST 2011


>So in this case, you MUST configure both the old and new credentials into
>the SP so that either key can be available for decryption.

Nate/Scott, it totally slipped my mind to do the SP configuration with
CredentialResolvers.  When we were doing attribute queries in SAML1 it
wasn't ever
needed to make a configuration on the SP side for key rollover, so I
didn't really consider it with encryption. I ended up adding the 2nd
cert/key and things worked.  Thanks

>I think you mean SP metadata. Strictly speaking, you don't need two
>encryption keys in SP metadata.

If you can't time the metadata loading with when the SP changes the
cert/key, then wouldn't you have to have 2?  If you had complete control
of everything I could see how you wouldn't need it 2 though.

Thanks for the help

Warren



More information about the users mailing list