Custom certificates for IDP

Chris Phillips Chris.Phillips at canarie.ca
Thu Jun 25 09:22:43 EDT 2015


Marco,

If you are referring how to migrate keys from an old 2.x install to a 3.x install, this is the process we followed:

Once you have your 3.x installation done, the metadata keys are located in /opt/shibboleth-idp/credentials and named idp-encryption[.key|.crt] and idp-signing[.key|.crt] (4 files).
These are the ones generated from a clean 3.x installation.

An existing 'old' install is usually on a separate host and has the  same directory (/opt/shibboleth-idp/credentials) with the important files  being idp.key and idp.crt.


  *   Secure copy these two files to the new host.
  *   Make a backup of the new keys on the 3.x install
  *   Stop the idp
  *   Copy idp.key to idp-encryption.key and idp-signing.key
  *   Copy idp.crt to idp-encryption.crt and idp-signing.crt
  *   Restart the idp.

The new 3.x IdP will now use the keys from the 'old' system and be a drop in replacement.  No metadata re-publishing required.
If you encounter problems signing onto something after the restart of the IdP is successful, use firefox+SAMLTracer to inspect which keys are being used to ensure the right ones are in play.

NOTE WELL: This is but one step in a migration and essentially allows the new server to present itself as the OLD server.
Be sure you are using the same or equivalent data for the user store as the old server. Other elements like the salts used for eduPersonTargetedID to be the same or you will disconnect users from their services.

Hope this is what you are looking for..

C

From: Marco Malavolti <marco.malavolti at garr.it<mailto:marco.malavolti at garr.it>>
Organization: Consortium GARR
Reply-To: Shib Users <users at shibboleth.net<mailto:users at shibboleth.net>>
Date: Thursday, June 25, 2015 at 6:54 AM
To: "users at shibboleth.net<mailto:users at shibboleth.net>" <users at shibboleth.net<mailto:users at shibboleth.net>>
Subject: Re: Custom certificates for IDP

Hi to all,

I re-open this thread to ask if someone know more on this problem.

We encounter this need when we try to restore an IdP from scratch without change the IdP's metadata (that contains the signing and the encryption certificates)...

Can somebody help me?

Thank you so much!
Marco


Il 18/05/2015 15.43, Andranik Hayrapetyan ha scritto:
Hi.

Is there a way to install Shibboleth IDP 3.1.1 with custom certificate and key? Or I have to install and than change them manually?

P.S. any documentation about this will be useful, because I am not strong at certificate staff.

Thanks in advance.




--
Marco Malavolti
Consortium GARR - Servizio IDEM GARR AAI
Via dei Tizii, 6 - I-00185 Roma
CF 97284570583 - PI 07577141000
skype: marco.mala
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20150625/4237adbe/attachment-0001.html>


More information about the users mailing list