Metadata signing certificate process - InCommon

Mark K. Miller max at psu.edu
Fri Mar 14 09:43:02 EDT 2014


On Fri, 14 Mar 2014, Vignesh, Vanna G. wrote:

> Our Idp consumes InCommon metadata and refreshes it every day. Now we need
> to change the url to production metadata aggregate. I don?t have problem
> with that. InCommon suggests to get a copy of metadata signing certificate.
> Can someone let me know the steps?

The InCommon staff have some wonderful documentation here:

https://spaces.internet2.edu/display/InCFederation/Shibboleth+Metadata+Config

Look in the "Configure the Shibboleth IdP" section.

> Once I get the new cert, should the security: Trust engine of incommon 
> in relying-party.xml  pointed to this new cert?

See directions reference above.

Hope this helps,

Max


More information about the users mailing list