sp key rollover

Cantor, Scott cantor.2 at osu.edu
Fri Apr 17 16:51:27 EDT 2015


> My boss asked me about this yesterday.  I don't see the original message
> from Canvas, but from what I understood they don't support multiple
> decryption keys on their side.

Yes, that basically prevents any proper rollover. I suppose we should consider a RFE at some point to actually attach a schedule as input to key selection. ;-(

>  It sounded like they were advising there
> would be a flag day, and everyone would have to change their locally-
> defined encryption key in lock step with Canvas.  Which if true, is obviously
> insane and broken.

Yeah, so, Salesforce did that on Twitter. So "insane" and "broken" is how you become a billionaire in 2015.

> And it also sounded like they're doing this solely b/c the Canvas *cert*
> containing the key expires on April 22 (?).  Which of course is a whole 'nother
> issue - the Shib IdP doesn't even look at the cert data when encryption, it
> just uses the public key.  (And of course they could just publish a new cert
> with the same public key, and avoid all the breakage, but sounds like they're
> not doing that.)

Right. This is why I now avoid enabling encryption with any vendors that are using non-self-signed certificates and not running Shibboleth, it basically guarantees they'll force a flag day on me, and it isn't worth it.

-- Scott



More information about the users mailing list