default IdP metadata for Shib IdP V3
Cantor, Scott
cantor.2 at osu.edu
Wed Jan 20 09:38:19 EST 2016
On 1/20/16, 8:10 AM, "users on behalf of Tom Scavo" <users-bounces at shibboleth.net on behalf of trscavo at gmail.com> wrote:
>I understand why the back-channel TLS and signing keys are different
>(because they represent completely different security models such that
>the compromise of one key does not necessarily imply compromise of the
>other) but I still don't understand why the signing certificate and
>the encryption certificate aren't the same. Can you explain?
It's bad key hygiene to use one key for both, just as with TLS, and the implications of changing them (or of one of them being compromised) are very different.
Changing an SP's key now is a really hard process to navigate even when everything's done 100% correctly by both sides because the same key is used for both. It was just a bad choice on my part.
-- Scott
More information about the users
mailing list