SP Key Rollover with IdP encryptAssertions="conditional"
Leung, Warren
wleung at it.ucla.edu
Thu Sep 22 16:50:33 BST 2011
>So in this case, you MUST configure both the old and new credentials into
>the SP so that either key can be available for decryption.
Nate/Scott, it totally slipped my mind to do the SP configuration with
CredentialResolvers. When we were doing attribute queries in SAML1 it
wasn't ever
needed to make a configuration on the SP side for key rollover, so I
didn't really consider it with encryption. I ended up adding the 2nd
cert/key and things worked. Thanks
>I think you mean SP metadata. Strictly speaking, you don't need two
>encryption keys in SP metadata.
If you can't time the metadata loading with when the SP changes the
cert/key, then wouldn't you have to have 2? If you had complete control
of everything I could see how you wouldn't need it 2 though.
Thanks for the help
Warren
More information about the users
mailing list