Google Apps Certificate

Cantor, Scott cantor.2 at osu.edu
Tue Jul 26 18:26:04 EDT 2016


On 7/26/16, 6:04 PM, "users on behalf of Lucia Siochi" <users-bounces at shibboleth.net on behalf of Lucia.Siochi at cpcc.edu> wrote:

>    I haven’t had to work with certificates and keys much, so this may be a stupid or non-
> sequitur question:

It's not, but you seem to be distinguishing things that are not in fact different. They're *all* keys belonging to the IdP. If you want to use more than one you can, but there is no sensible reason to do so.

> From what I’ve been able to find out, when setting up IdPv3 for Google Apps, you upload
> the pem file for the idp’s certificate/key. Is it possible to use different key/cert/pem
> files for Google instead of re-using the ones the idp uses in IDP_HOME/credentials? Or do
> you *have* to use the idp’s?

See above. They are all the IdP's. Why would you think otherwise, and why would you want to use two instead of one?

> If you can use a different set for Google, how do you tell the idp that those are the ones
> to use for Google, (in the relying-party perhaps?)?

Yes.

https://wiki.shibboleth.net/confluence/display/IDP30/SecurityConfiguration

Per-Profile Credential

There is no reason to do this. You do it when you have to, you don't volunteer to do it.

-- Scott




More information about the users mailing list