Renewing Shibboleth Certificate

Cantor, Scott cantor.2 at osu.edu
Tue Sep 11 09:52:00 EDT 2012


On 9/11/12 7:29 AM, "Wavyne Belance" <wbelance at luc.edu> wrote:
>
>The certificate is updated in my metadata and its location and  the key
>are in the relying-party.xml file. I also see the saml2 assertion being
>sent with the correct certificate when I turn debugging on. Where did I
>go wrong?

You're using the wrong key, the metadata's wrong, or the SP doesn't have
the metadata you think it does.

>Are there step by step guides to renewing the Shibboleth certificate?

Several. But renewing a certificate is mostly irrelevant and won't cause
this error. Changing a key is the only time it matters. Renewal does not
involve changing a key.

If you really changed the key, then you would need to follow something
along the lines of 
https://wiki.shibboleth.net/confluence/display/SHIB2/IdPKeyRollover

-- Scott




More information about the users mailing list