Relying party specific Credential and Metadata
Sean McHugh
sean8sean at gmail.com
Thu Aug 29 15:49:30 EDT 2013
After some fruitless searching to confirm this, I present this simple
scenario:
- I have an IdP with many relying parties, most of them internal, some
external. We've used the self-signed credential / cert generated at install
and never had the need to change this or supply metadata other than what is
produced at /idp/profile/SAML/Metadata
- I have a new service provider (Equifax) that requires a cert issued by a
trusted commercial CA
I've obtained said cert, placed it and the private key in /credentials and
modified the relying-party.xml configuration to utilize this cert for both
signing and encryption
with the relying party.
So, my questions:
- Do I also need to create a jks keystore as well? Where is this
referenced in the config?
- When giving my IdP metadata to the new relying party, I assume that,
considering all other aspects of my IdP are the same as for my other
relying-parties, I can simply replace the inline
x509 base64 text in my usual metadata info and give that to the
relying-party
Any insight would be much appreciated.
--sean
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130829/9b2292a9/attachment.html
More information about the users
mailing list