Handling IdP cert rollover

Peter Schober peter.schober at univie.ac.at
Mon Feb 23 10:48:58 EST 2015


* MikeWho <who at me.com> [2015-02-23 16:44]:
> We're about to receive an updated IdP cert to import into our
> Shibboleth SP, am I right in thinking that if the updated IdP
> metadata contains two KeyDescriptors, one with the existing
> about-to-expire cert, the other being the new cert, then the
> rollover can happen 'seamlessly' without a manual switch-over on our
> part?

If the rollover is done properly, then yes, there's nothing to be done
on the SP.
You first said you'll recieve "an updated IdP cert to import into our
Shibboleth SP" and then talk about "metadata contain[ing] two
KeyDescriptors".
So is it one or the other, or both (do you receive the key and need to
manipulate the SAML metadata on behalf of the IDP)?
-peter


More information about the users mailing list