Using a second signing certificate
Jason Gauthier
jgauthier at lastar.com
Mon Jul 15 13:16:40 EDT 2013
>You can't do key rollover unless the metadata is decoupled from the configuration so that it can be altered ahead of the change. InCommon has a >number of wiki pages that describe how this works in some detail (there are some in the Shibboleth wiki as well, but more specifically geared to >the software).
Okay. This makes sense, but is still a confusing concept for me.
>But basically you are guaranteed to break if you start signing with a key before every downstream system has metadata containing that key. I >would imagine that's the source of your problem, but you didn't really provide specifics as to what the state was when it broke.
Yes, more or less. I actually had 2 Shib systems break, and two vendor systems. Those vendors had me supply a certificate for signing.
On 07/09, my ADFS server "switched" keys, and all the vendors I supplied the signing key to previously just broke.
Since I don't have control over their systems, I am trying to understand this from the perspective of what I do have control over. Which is my ADFS and a couple Shib instances.
>This metadata is signed, and I had to remove all of the signature data
>following these instructions:
>Metadata signing is a separate consideration, and depends on how you're managing trust between systems. But in general you cannot, for the >above reason, rely on ADFS or any other system to directly generate metadata from a configuration and then expect key rollover to be >successful.
That makes sense. I don't really have expectations, but more looking into what process I can use so that next year this doesn't break out without anyone understanding why, or preferably what I can do to put all the pieces in place now for longevity.
I'm still not certain what those pieces are.
>But needing to modify the metadata generated by a software product is the norm, not the exception, because of how it's used.
Okay. It's comforting to know that editing the metadata is common. I guess I need to figure out how to handle key roll over with Shib, in my environment... and maybe discuss this with my vendors as well.
More information about the users
mailing list