Handling IdP cert rollover

Cantor, Scott cantor.2 at osu.edu
Mon Feb 23 10:52:43 EST 2015


On 2/23/15, 3:43 PM, "MikeWho" <who at me.com> wrote:
>
>We're about to receive an updated IdP cert to import into our Shibboleth 
>SP,
>am I right in thinking that if the updated IdP metadata contains two
>KeyDescriptors, one with the existing about-to-expire cert, the other 
>being
>the new cert, then the rollover can happen 'seamlessly' without a manual
>switch-over on our part?

When it's signing alone and you're not encrypting anything to the IdP, yes.

You shouldn't have to update certificates in any case, only keys.

>Does anything else need to be changed on our part? Does the order of the
>KeyDescriptors in the MetaData have any significance?

Yes, the order they're tried when verifying signtaures or TLS keys.

-- Scott



More information about the users mailing list