How do I change the certificate of a Shibboleth service provider?

Cantor, Scott cantor.2 at osu.edu
Wed Jul 18 15:41:12 EDT 2012


> How do I change the certificate of a Shibboleth service provider? Full details
> of the problem
> here:http://security.stackexchange.com/questions/17312/how-do-i-change-
> the-certificate-of-a-shibboleth-service-provider

Please post future questions here, not somewhere else. Asking people to go lookup your question isn't really polite on mailing lists.

Your problem starts with a false premise: you don't need to change it to a Verisign certificate and in fact should not, for many good reasons. It doesn't mean what you want it to mean, especially if you're sticking the certificate inside your metadata. At that point the key is the only thing that matters.

Leaving that aside, if the IdP isn't accepting it, then either your SP isn't using it, or the metadata isn't accurate yet. Your message says that you "added" the new keypair, but if that's true, then it isn't going to do anything with it. It won't magically switch unless you specify a rule to use that certificate with that IdP (via a RelyingParty element) or unless you reorder them so that it's the first one in the config.

-- Scott



More information about the users mailing list