Changing the certs

Tom Scavo trscavo at gmail.com
Mon Jul 14 16:02:46 EDT 2014


On Mon, Jul 14, 2014 at 3:54 PM, Vignesh, Vanna G. <vignesh at musc.edu> wrote:
> If we change the Idp certificate, do we have to inform all the service
> providers about the new cert?

I see you are an InCommon participant so I will give the InCommon answer :-)

https://spaces.internet2.edu/x/dJiKAQ

Take a look at the parent page as well, but the above page basically
tells you what you need to know.

> What are the consequences of using expired cert?

Some SAML software is known to react badly to expired certs in
metadata, mostly Microsoft AD FS. Shibboleth, simpleSAMLphp, and other
"well behaved" software will ignore this detail since the public key
in the metadata is all that really matters.

Tom


More information about the users mailing list