commercial cert for idp
Mark K. Miller
max at psu.edu
Thu Dec 19 14:39:44 EST 2013
On Thu, 19 Dec 2013, Qian, Yi wrote:
> Hello,
>
> We have shibboleth idp with self signed certificate and federated with many
> SPs, but recently a vendor requires us to use commercial certificate for the
> federation.
What federation are you and the vendor a member of? What are their
recommendations with regard to certs?
> I saw on the shib wiki that sp can have credential resolver chaining to use
> multiple cert, I can't find similar topic related to the idp.
>
> Chance of the vendor allowing us to use self signed cert is very low, we
> would like not to set up another Idp just for this vendor. So what is my
> options?
It would seem to me that the federation you're both members of establishes
these rules with the input of the community of members. These rules
aren't made by any single member of the federation.
If you happen to be doing a bi-lateral direct trust with this vendor this
is just another reason why that's a terrible idea compared to an actual,
organized federation.
> Regards,
> Yi
Hope that helps,
Max
More information about the users
mailing list