sp key rollover
Cantor, Scott
cantor.2 at osu.edu
Fri Apr 17 16:32:15 EDT 2015
> We're using Canvas. The cert they're using expires on 4/22, and they've sent
> us a new cert. They do not publish metadata - we've got a local copy.
What is the key being used for? There is no way for you to unilaterally roll an encryption key. They have to have the ability to load both keys and decrypt with either. For signing, just add it to the metadata and you're done, but I doubt they're using it for that.
> Ideally the metadata would contain both the new and old certs so we don't
> need to coordinate a real-time roll over.
That doesn't work for encryption. They MUST also load both or you're done here.
> Any suggestions? Rollover suggest to me that they certs should be able to
> co-exist..
They co-exist fine. It still only encrypts with one key at a time. Key rollover is a mutual responsibility. If they don't play their part, you can't play it for them.
-- Scott
More information about the users
mailing list