SP trust fabric certificate expiring
Cantor, Scott
cantor.2 at osu.edu
Fri Jun 22 21:01:30 BST 2012
On 6/22/12 2:01 PM, "Scott Klawitter" <sklawitter at ebsco.com> wrote:
>I wanted to see if there is a generally acceptable certificate that
>federations will accept, or is the self-signed cert the right one. Also
>is there a generally acceptable lifetime for the cert? 5, 10, 20 years?
The lifetime of the key is based on the metadata, and not the certificate.
The recommendation from the project is to use as long as is practical to
avoid it expiring and breaking other software.
The guidelines for *key* lifetime will depend on federations or partners
and isn't something one sees much attention on so far.
-- Scott
More information about the users
mailing list