SP ability to handle multiple idp certs or idp metadata?

Tom Scavo trscavo at gmail.com
Fri Jun 17 08:00:42 EDT 2016


On Fri, Jun 17, 2016 at 5:05 AM, Luke Alexander <luke at brandwatch.com> wrote:
>
> I'd like to know if there is some documentation detailing how (if at all
> possible?) an SP can be configured against an IDP who is in the process
> of updating their certs - so that it may handle both old and new certs
> (or old/new metadata) at the same time; meaning that when the time comes
> for the old certificate to be expired there is a smoother transition to
> the new?

This is called certificate migration or key rollover. In the case you
described, the IdP does all the work. If all SP partners refresh
metadata regularly, say, daily, the IdP simply introduces a new
certificate into metadata, waits one day, then starts signing
responses with the new key. It can then remove the old certificate
from metadata at its leisure.

Tom


More information about the users mailing list