Shib IdP v3: Which certificate do you upload to InCommon?
Karla Borecky
kborecky at smith.edu
Mon Mar 14 14:59:21 EDT 2016
Well, we brought up a new IdP, with new certs and a new entityID. I've
already been working with all of our SPs to get them the new metadata and
certs and so forth, if that's what you mean about a long process. (And yes,
it's been a long haul.)
That's the situation. We only have a couple of SPs that use our InCommon
metadata, but I need to change it to point to the new one. So, the question
remains: which one should I use? (Not encryption, I know that now.) What
would someone do if their v3 IdP were a new addition to InCommon?
Thanks,
Karla
On Mon, Mar 14, 2016 at 2:47 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:
> > I was about to change our InCommon IdP information to list our v3 IdP,
> but
> > I'm not sure which certificate I should be uploading. The signing one?
> All
> > three?
>
> You shouldn't be changing anything. Your IdP should be using the same
> signing key as before. If you were using it for SOAP, then you should also
> be using that key for your container's SOAP port. The only reason you
> should be changing a key is if it's compromised, or if you want to roll out
> a new one, in which case you have a very long process ahead and you can't
> do it by just changing the key all at once.
>
> InCommon does not have support for encryption-only keys so there's nothing
> you can do with the separate key at the moment in the federation's mtadata
> interface.
>
> If there's something in the SecurityAndNetworking topic you don't
> understand, you should absolutely stop until you do, and ask about it.
>
> -- Scott
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
--
Karla Borecky
Systems Administrator
ITS
Smith College
Northampton, MA 01063
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160314/e9312393/attachment.html>
More information about the users
mailing list