Upgrade SP with intermediate certificate

Avirup Neogi aneogi13 at gmail.com
Mon Jun 27 11:24:40 EDT 2016


Well ! Following section is from the UK Federation site (
http://www.ukfederation.org.uk/content/Documents/GetCertificatesSh2IdP) :

"To set up a Shibboleth 2.x IdP entity within the UK federation you will
normally require two X.509 digital certificates:
a trust-fabric certificate for machine-to-machine use, and
a browser-facing certificate that users will see

These two certificates are used for different purposes and have different
properties:
A self-signed certificate with a lifetime of 10 or 20 years is recommended
for the trust fabric certificate
An SSL certificate from a commercial Certification Authority (CA) is
required for the browser-facing certificate"


To come to the point raised in my initial post. We are planning for a
certificate rollover in our sp since the existing certificate is expiring
next month. Previously we had a single certificate but now we have an
intermediate certificate in addition to the certificate. My question is
what should be the correct way to incorporate the certificate in the sp
metadata xml. The metadata is an xml file created manually
("/sp-metadata.xml"). It is NOT the auto generated one from Shibboleth.sso
(i.e. "/Shibboleth.sso/Metadata").



On Mon, Jun 27, 2016 at 8:38 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:

> > My question was for sp certificate rollover as mentioned by the following
> > Shibboleth federations:
>
> And that has nothing to do with changing a browser-facing certificate.
>
> -- Scott
>
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160627/0b640476/attachment.html>


More information about the users mailing list