Upgrade SP with intermediate certificate
Cantor, Scott
cantor.2 at osu.edu
Mon Jun 27 11:33:08 EDT 2016
> "To set up a Shibboleth 2.x IdP entity within the UK federation you will
> normally require two X.509 digital certificates:
> a trust-fabric certificate for machine-to-machine use, and
> a browser-facing certificate that users will see
And the latter has nothing to do with the former, and only the former should be in the metadata.
> To come to the point raised in my initial post. We are planning for a certificate
> rollover in our sp since the existing certificate is expiring next month.
You said your *browser facing certificate* was changing. If that's in the metadata, you screwed up, so now you might have to fix that, and that raises a different set of issues. I didn't assume that was the case since you didn't say that. If it's not in the metadata, then the SP should know nothing about it and that's the answer to your question.
> Previously we had a single certificate but now we have an intermediate
> certificate in addition to the certificate. My question is what should be the
> correct way to incorporate the certificate in the sp metadata xml.
The correct way is NOT to do it. I don't know what else you want to me to say.
-- Scott
More information about the users
mailing list