SP trust fabric certificate expiring
Ian Young
ian at iay.org.uk
Fri Jun 22 20:17:48 BST 2012
On 22 Jun 2012, at 19:01, Scott Klawitter wrote:
> Some federations like the UKfederation ARE NOT ACCEPTING VeriSign CERTIFICATES ANYMORE and recommend using a self-signed cert.
Just to clarify: the UK federation does indeed strongly recommend the use of long-lived, self-signed certificates now. However, we will still accept essentially any other certificate if you really need to use them, for example because you have to do so for use with other federations.
We no longer have VeriSign as a qualified CA: they changed their roots and intermediates, so that the VeriSign *products* we certified are no longer being issued by them. This means that a VeriSign certificate can still be embedded, but through the slightly more stringent process we use for self-signed certificates rather than the less stringent one we were able to use with qualified CAs.
Hope that helps,
-- Ian
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20120622/350d494f/attachment.html
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 4813 bytes
Desc: not available
Url : http://shibboleth.net/pipermail/users/attachments/20120622/350d494f/attachment.bin
More information about the users
mailing list