Q: Shib IdP behaviour for key roll over and ADFS

Chris Phillips Chris.Phillips at canarie.ca
Tue Feb 18 10:48:04 EST 2014


I'm in the position of doing key rollover on an ADFS entity in our SAML2 metadata.

My current metadata record has one certificate with no 'use=signing' designation and it will expire shortly.

I have a new (auto generated by ADFS) cert in hand that I can put into the metadata and intend to apply the use=signing designation for that and only that key.

Given the state described above:

 - Will the Shibboleth IdPs automatically use the most recent certificate or the older one until it expires?

I presume that once IdP's see a newer certificate they will use that one, but am unsure.

-  Also, can I co-mingle the certificates with distinct use=xxxxx designations without issue?
(i.e. Must I post my new cert like my other one currently in the metadata with no 'use=signing' designation?)

I presume that this is ok as well to do because ADFS has both certificates that it can properly validate the signatures whether it is signed with the old cert or new cert.

The last question I have is that I also presume that once the older cert is expired that I MAY leave it in the metadata past the expiry date and it will not be used by Shibboleth IdPs, but only the newest one.

I realize that this is ADFS focused(as an SP and gateway to Sharepoint), but I'm really asking about the Shibboleth IdP behaviour in a key roll over situation and have read this [1] already and seeking a bit more clarity/confirmation about expected behaviour.

Thanks in advance.

Chris.

(posting to the shib-users list rather than shib-dev where the other ADFS related question has popped up.)

[1] https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPMultipleCredentials
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20140218/30c50654/attachment.html 


More information about the users mailing list