Renewing Shibboleth Certificate

Wavyne Belance wbelance at luc.edu
Thu Sep 13 10:18:42 EDT 2012


Martin
 
This document has been very helpful... I truly appreciate your help.
 
Have a great day
Wavyne Belance

>>> Martin Haase <Martin.Haase at DAASI.de> 9/12/2012 10:42 AM >>>
Hi Wavyne,

if it is of any help - I find the following two pages very useful:

https://www.switch.ch/aai/docs/shibboleth/SWITCH/sp-certificate-rollover.html

https://www.switch.ch/aai/docs/shibboleth/SWITCH/idp-certificate-rollover.html

Cheers,
Martin

Am 12.09.2012 16:49, schrieb Wavyne Belance:


Hello Scott 
 
Thanks for your explanation. I have a few follow-up questions:
 
When the certificate in the metadata file expires, then I should not
make changes within the relying-party file to reflect the renewed cert?
 
As you stated when you renewed the certificate, you don't have to
change the key in the relying-party file, but the SP gets a different
certificate than the one in the metadata if the key isn't also renewed,
correct?
 
When would I need to update the key and the certificate in the
relying-party file?
 
And what certificate should be in the metadata file? The CA signed
certificate or the server issued certificate being referenced in the
relying-party file?
 
Thanks again
Wavyne Belance

>>> "Cantor, Scott" <cantor.2 at osu.edu> ( mailto:cantor.2 at osu.edu )
9/11/2012 8:52 AM >>>
On 9/11/12 7:29 AM, "Wavyne Belance" <wbelance at luc.edu> (
mailto:wbelance at luc.edu ) wrote:
>
>The certificate is updated in my metadata and its location and  the
key
>are in the relying-party.xml file. I also see the saml2 assertion
being
>sent with the correct certificate when I turn debugging on. Where did
I
>go wrong?

You're using the wrong key, the metadata's wrong, or the SP doesn't
have
the metadata you think it does.

>Are there step by step guides to renewing the Shibboleth certificate?

Several. But renewing a certificate is mostly irrelevant and won't
cause
this error. Changing a key is the only time it matters. Renewal does
not
involve changing a key.

If you really changed the key, then you would need to follow something
along the lines of 
https://wiki.shibboleth.net/confluence/display/SHIB2/IdPKeyRollover

-- Scott


--
To unsubscribe from this list send an email to
users-unsubscribe at shibboleth.net


--
To unsubscribe from this list send an email to
users-unsubscribe at shibboleth.net
-- 
-----------------------------------------------------------------------
Dr. Martin Haase
DAASI International GmbH                   phone:     +49 7071
407109-6
Europaplatz 3                              Fax  :     +49 7071
407109-9
D-72072 Tübingen                           email:
Martin.Haase at DAASI.deGermany                                    Web  :  
http://www.daasi.de
Directory Applications for Advanced Security and Information
Management
-----------------------------------------------------------------------
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20120913/6ecbde37/attachment-0001.html 


More information about the users mailing list