Relying party specific Credential and Metadata

Sean McHugh sean8sean at gmail.com
Thu Aug 29 15:49:30 EDT 2013


After some fruitless searching to confirm this, I present this simple
scenario:

- I have an IdP with many relying parties, most of them internal, some
external.  We've used the self-signed credential / cert generated at install
and never had the need to change this or supply metadata other than what is
produced at /idp/profile/SAML/Metadata

- I have a new service provider (Equifax) that requires a cert issued by a
trusted commercial CA

I've obtained said cert, placed it and the private key in /credentials and
modified the relying-party.xml configuration to utilize this cert for both
signing and encryption
with the relying party.

So, my questions:

- Do I also need to create a jks keystore as well?  Where is this
referenced in the config?
- When giving my IdP metadata to the new relying party, I assume that,
considering all other aspects of my IdP are the same as for my other
relying-parties, I can simply replace the inline
x509 base64 text in my usual metadata info and give that to the
relying-party

Any insight would be much appreciated.

--sean
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130829/9b2292a9/attachment.html 


More information about the users mailing list