Upgrade SP with intermediate certificate
Alex Stuart
alex.stuart at ed.ac.uk
Mon Jun 27 11:35:03 EDT 2016
Hi Avirup
It's Alex from the UK federation support team here. Our documentation
page also states that "The browser-facing SSL certificate does not
appear in metadata (unless it happens also to be the trust fabric
certificate)." However, your SP is registered with a CA-certified
certificate in the trust fabric, and I assume that you've also got this
certificate configured for browser-facing purposes.
It'll take a bit of work to roll your certificate(s) over without loss
of service for your customers, and as there's an open call in our Call
Management System for your SP's certificate rollover, could you continue
the discussion there? I can talk you through the steps to roll over the
certificate seamlessly.
Alex
On 27/06/2016 16:24, Avirup Neogi wrote:
> Well ! Following section is from the UK Federation site
> (http://www.ukfederation.org.uk/content/Documents/GetCertificatesSh2IdP) :
>
> "To set up a Shibboleth 2.x IdP entity within the UK federation you will
> normally require two X.509 digital certificates:
> a trust-fabric certificate for machine-to-machine use, and
> a browser-facing certificate that users will see
>
> These two certificates are used for different purposes and have
> different properties:
> A self-signed certificate with a lifetime of 10 or 20 years is
> recommended for the trust fabric certificate
> An SSL certificate from a commercial Certification Authority (CA) is
> required for the browser-facing certificate"
>
>
> To come to the point raised in my initial post. We are planning for a
> certificate rollover in our sp since the existing certificate is
> expiring next month. Previously we had a single certificate but now we
> have an intermediate certificate in addition to the certificate. My
> question is what should be the correct way to incorporate the
> certificate in the sp metadata xml. The metadata is an xml file created
> manually ("/sp-metadata.xml"). It is NOT the auto generated one from
> Shibboleth.sso (i.e. "/Shibboleth.sso/Metadata").
>
>
>
> On Mon, Jun 27, 2016 at 8:38 PM, Cantor, Scott <cantor.2 at osu.edu
> <mailto:cantor.2 at osu.edu>> wrote:
>
> > My question was for sp certificate rollover as mentioned by the following
> > Shibboleth federations:
>
> And that has nothing to do with changing a browser-facing certificate.
>
> -- Scott
>
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
> <mailto:users-unsubscribe at shibboleth.net>
>
>
>
>
--
Alex Stuart
Team Leader - Federated Access Management
EDINA, University of Edinburgh
The University of Edinburgh is a charitable body, registered in
Scotland, with registration number SC005336.
More information about the users
mailing list