removing old certificate from metadata
Klingenstein, Nate
nklingenstein at calstate.edu
Wed Aug 10 14:52:43 EDT 2016
Izz,
1. Just removing the old certificate from the metadata with InCommon
I can't think of a way that would be unsafe.
2. Leaving the certificate which is about to expire, since it isn’t used
a. For informational purposes. Are there cases where configs would reject metadata if an expired certificate is in it, although no longer utilized?
That's a better question. I would rephrase:
If the certificate is not bad right now, are all the providers in InCommon using implementations that skim over a bad certificate, even if they aren't using it?
I would suspect yes and InCommon's policies should reflect that, but "stranger things have happened".
Hope this helps,
Nate.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160810/503d8e8c/attachment.html>
More information about the users
mailing list