Using a second signing certificate
Cantor, Scott
cantor.2 at osu.edu
Mon Jul 15 11:14:42 EDT 2013
On 7/15/13 11:09 AM, "Jason Gauthier" <jgauthier at lastar.com> wrote:
>I am using Shibboleth as a service provider for an ADFS idP. I have two
>signing certificates. One that expires on 07/28, and the other that
>becomes (became) effective on 07/09. Because of the change it caused all
>of my Shib service providers to stop working.
That cannot be the cause. Shibboleth SPs don't stop working because of
certificate expirations, only if you provide incorrect metadata.
>How can I configure Shibboleth to allow both certificates as being valid?
The certificates don't have to be valid, and you should not change keys
because of a certificate expiring. Or ever, unless you have an actual
reason based on key compromise or some legitimate justification that the
key may be vulnerable.
Regardless, all you have to do is enumerate the keys in the metadata.
-- Scott
More information about the users
mailing list