Renewing Shibboleth Certificate

Martin Haase Martin.Haase at DAASI.de
Wed Sep 12 11:42:31 EDT 2012


Hi Wavyne,

if it is of any help - I find the following two pages very useful:

https://www.switch.ch/aai/docs/shibboleth/SWITCH/sp-certificate-rollover.html


https://www.switch.ch/aai/docs/shibboleth/SWITCH/idp-certificate-rollover.html

Cheers,
Martin


Am 12.09.2012 16:49, schrieb Wavyne Belance:
> Hello Scott
>  
> Thanks for your explanation. I have a few follow-up questions:
>  
> When the certificate in the metadata file expires, then I should not
> make changes within the relying-party file to reflect the renewed cert?
>  
> As you stated when you renewed the certificate, you don't have to
> change the key in the relying-party file, but the SP gets a different
> certificate than the one in the metadata if the key isn't also
> renewed, correct?
>  
> When would I need to update the key and the certificate in the
> relying-party file?
>  
> And what certificate should be in the metadata file? The CA signed
> certificate or the server issued certificate being referenced in the
> relying-party file?
>  
> Thanks again
> Wavyne Belance
>
> >>> "Cantor, Scott" <cantor.2 at osu.edu> 9/11/2012 8:52 AM >>>
> On 9/11/12 7:29 AM, "Wavyne Belance" <wbelance at luc.edu> wrote:
> >
> >The certificate is updated in my metadata and its location and  the key
> >are in the relying-party.xml file. I also see the saml2 assertion being
> >sent with the correct certificate when I turn debugging on. Where did I
> >go wrong?
>
> You're using the wrong key, the metadata's wrong, or the SP doesn't have
> the metadata you think it does.
>
> >Are there step by step guides to renewing the Shibboleth certificate?
>
> Several. But renewing a certificate is mostly irrelevant and won't cause
> this error. Changing a key is the only time it matters. Renewal does not
> involve changing a key.
>
> If you really changed the key, then you would need to follow something
> along the lines of
> https://wiki.shibboleth.net/confluence/display/SHIB2/IdPKeyRollover
>
> -- Scott
>
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
>
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net

-- 
-----------------------------------------------------------------------
Dr. Martin Haase
DAASI International GmbH                   phone:     +49 7071 407109-6
Europaplatz 3                              Fax  :     +49 7071 407109-9
D-72072 Tübingen                           email: Martin.Haase at DAASI.de
Germany                                    Web  :   http://www.daasi.de

Directory Applications for Advanced Security and Information Management
-----------------------------------------------------------------------

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20120912/ed160159/attachment-0001.html 
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 2345 bytes
Desc: S/MIME Kryptografische Unterschrift
Url : http://shibboleth.net/pipermail/users/attachments/20120912/ed160159/attachment-0001.bin 


More information about the users mailing list