Changing the certs
Tom Scavo
trscavo at gmail.com
Mon Jul 14 16:02:46 EDT 2014
On Mon, Jul 14, 2014 at 3:54 PM, Vignesh, Vanna G. <vignesh at musc.edu> wrote:
> If we change the Idp certificate, do we have to inform all the service
> providers about the new cert?
I see you are an InCommon participant so I will give the InCommon answer :-)
https://spaces.internet2.edu/x/dJiKAQ
Take a look at the parent page as well, but the above page basically
tells you what you need to know.
> What are the consequences of using expired cert?
Some SAML software is known to react badly to expired certs in
metadata, mostly Microsoft AD FS. Shibboleth, simpleSAMLphp, and other
"well behaved" software will ignore this detail since the public key
in the metadata is all that really matters.
Tom
More information about the users
mailing list