Handling IdP cert rollover

Peter Schober peter.schober at univie.ac.at
Mon Feb 23 11:02:01 EST 2015


* MikeWho <who at me.com> [2015-02-23 16:58]:
> Thanks Peter, my wording was a little ambiguous. Typically the IdPs send us
> both the updated cert and metadata files, but we exclusively use the
> metadata file (I think it's a good policy for each party to edit/own their
> own metadata rather than tinkering/tweaking someone else's).

I think you're after step 2, then, in the list of steps layed out at
https://wiki.shibboleth.net/confluence/display/SHIB2/IdPKeyRollover
I.e., the IDP has created a new key pair, added it to their metadata,
and given you updated metadata containing both keys.
Now you wait until the IDP starts using the new key and then they'll
probably send you updated metadata again, or ask you to remove the old
key.
I.e., if you had a streamlined process for exchanging metadata you
wouldn't even need to know any of that happened.
-peter


More information about the users mailing list