commercial cert for idp

Mark K. Miller max at psu.edu
Thu Dec 19 14:39:44 EST 2013


On Thu, 19 Dec 2013, Qian, Yi wrote:

> Hello,
> 
> We have shibboleth idp with self signed certificate and federated with many
> SPs, but recently a vendor requires us to use commercial certificate for the
> federation.

What federation are you and the vendor a member of?  What are their 
recommendations with regard to certs?

> I saw on the shib wiki that sp can have credential resolver chaining to use
> multiple cert, I can't find similar topic related to the idp.
> 
> Chance of the vendor allowing us to use self signed cert is very low, we
> would like not to set up another Idp just for this vendor. So what is my
> options?

It would seem to me that the federation you're both members of establishes 
these rules with the input of the community of members.  These rules 
aren't made by any single member of the federation.

If you happen to be doing a bi-lateral direct trust with this vendor this 
is just another reason why that's a terrible idea compared to an actual, 
organized federation.

> Regards,
> Yi

Hope that helps,

Max


More information about the users mailing list