Handling IdP cert rollover
Cantor, Scott
cantor.2 at osu.edu
Mon Feb 23 10:52:43 EST 2015
On 2/23/15, 3:43 PM, "MikeWho" <who at me.com> wrote:
>
>We're about to receive an updated IdP cert to import into our Shibboleth
>SP,
>am I right in thinking that if the updated IdP metadata contains two
>KeyDescriptors, one with the existing about-to-expire cert, the other
>being
>the new cert, then the rollover can happen 'seamlessly' without a manual
>switch-over on our part?
When it's signing alone and you're not encrypting anything to the IdP, yes.
You shouldn't have to update certificates in any case, only keys.
>Does anything else need to be changed on our part? Does the order of the
>KeyDescriptors in the MetaData have any significance?
Yes, the order they're tried when verifying signtaures or TLS keys.
-- Scott
More information about the users
mailing list