Using a second signing certificate

Cantor, Scott cantor.2 at osu.edu
Mon Jul 15 11:14:42 EDT 2013


On 7/15/13 11:09 AM, "Jason Gauthier" <jgauthier at lastar.com> wrote:

>I am using Shibboleth as a service provider for an ADFS idP.  I have two
>signing certificates. One that expires on 07/28, and the other that
>becomes (became) effective on 07/09.  Because of the change it caused all
>of my Shib service providers to stop working.

That cannot be the cause. Shibboleth SPs don't stop working because of
certificate expirations, only if you provide incorrect metadata.

>How can I configure Shibboleth to allow both certificates as being valid?

The certificates don't have to be valid, and you should not change keys
because of a certificate expiring. Or ever, unless you have an actual
reason based on key compromise or some legitimate justification that the
key may be vulnerable.

Regardless, all you have to do is enumerate the keys in the metadata.

-- Scott




More information about the users mailing list