Upgrade SP with intermediate certificate

Cantor, Scott cantor.2 at osu.edu
Mon Jun 27 11:52:52 EDT 2016


> It'll take a bit of work to roll your certificate(s) over without loss
> of service for your customers, and as there's an open call in our Call
> Management System for your SP's certificate rollover, could you continue
> the discussion there? I can talk you through the steps to roll over the
> certificate seamlessly.

As a preliminary piece of advice, the best choice in that event is to *initially* just fork them. Leave the expired or expiring SSL keypair in the metadata and in the SP configuration, and get the browser-facing change done. Then it becomes a standard key rollover in the metadata, and at least you don't repeat the same mistake. Generate a self-signed keypair to migrate to in the metadata. All of which is what I would expect the UK staff to advise you to do.

What you don't want after the end of a ton of work and pain is to be just as screwed as you started out.

-- Scott



More information about the users mailing list