Handling IdP cert rollover

MikeWho who at me.com
Mon Feb 23 10:43:52 EST 2015


Hi all,

We're about to receive an updated IdP cert to import into our Shibboleth SP,
am I right in thinking that if the updated IdP metadata contains two
KeyDescriptors, one with the existing about-to-expire cert, the other being
the new cert, then the rollover can happen 'seamlessly' without a manual
switch-over on our part?

Does anything else need to be changed on our part? Does the order of the
KeyDescriptors in the MetaData have any significance?

Many thanks again for any assistance!
Mike.



--
View this message in context: http://shibboleth.1660669.n2.nabble.com/Handling-IdP-cert-rollover-tp7611823.html
Sent from the Shibboleth - Users mailing list archive at Nabble.com.


More information about the users mailing list