sp key rollover

Brent Putman putmanb at georgetown.edu
Fri Apr 17 16:46:07 EDT 2015



On 4/17/15 4:32 PM, Cantor, Scott wrote:
> What is the key being used for? There is no way for you to unilaterally roll an encryption key. They have to have the ability to load both keys and decrypt with either.
> That doesn't work for encryption. They MUST also load both or you're done here.

My boss asked me about this yesterday.  I don't see the original
message from Canvas, but from what I understood they don't support
multiple decryption keys on their side.  It sounded like they were
advising there would be a flag day, and everyone would have to change
their locally-defined encryption key in lock step with Canvas.  Which
if true, is obviously insane and broken.  Again, this might not be the
case, but that's what I was lead to believe - the email from them
apparently says something to the effect of "you must update your Canvas
encryption key on date X, or things will break".

And it also sounded like they're doing this solely b/c the Canvas
*cert* containing the key expires on April 22 (?).  Which of course is
a whole 'nother issue - the Shib IdP doesn't even look at the cert data
when encryption, it just uses the public key.  (And of course they
could just publish a new cert with the same public key, and avoid all
the breakage, but sounds like they're not doing that.)



-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20150417/a5333df0/attachment.html 


More information about the users mailing list