SP ability to handle multiple idp certs or idp metadata?
Luke Alexander
luke at brandwatch.com
Fri Jun 17 08:23:28 EDT 2016
On 17 June 2016 at 13:00, Tom Scavo <trscavo at gmail.com> wrote:
> On Fri, Jun 17, 2016 at 5:05 AM, Luke Alexander <luke at brandwatch.com>
> wrote:
> >
> > I'd like to know if there is some documentation detailing how (if at all
> > possible?) an SP can be configured against an IDP who is in the process
> > of updating their certs - so that it may handle both old and new certs
> > (or old/new metadata) at the same time; meaning that when the time comes
> > for the old certificate to be expired there is a smoother transition to
> > the new?
>
> This is called certificate migration or key rollover. In the case you
> described, the IdP does all the work. If all SP partners refresh
> metadata regularly, say, daily, the IdP simply introduces a new
> certificate into metadata, waits one day, then starts signing
> responses with the new key. It can then remove the old certificate
> from metadata at its leisure.
>
>
Ah yes, this makes sense, unfortunately the IDP in question is running
ADFS3 and the only way I found to handle it's metadata is to 'correct it'
using the ADFS2Fed.py script so that the SP is able to use it; meaning that
we are using a static metadata file for this IDP, perhaps I'm doing
something wrong with this too and there is a magic setting for the SP to
happily accept any ADFS3 formatted metadata?
--
*Download our latest free guide here
<https://www.brandwatch.com/competitive-intelligence-guide/>*
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160617/4f9d0d81/attachment.html>
More information about the users
mailing list