Shib IdP v3: Which certificate do you upload to InCommon?
Nate Klingenstein
nate.klingenstein at utah.edu
Mon Mar 14 15:07:34 EDT 2016
Karla,
The short answer is, the signing certificate.
The long answer is that it’s up to the metadata. Metadata for providers can contain keys for signing, encryption, or both, which is the default. There’s almost nothing that the IdP needs to receive encrypted, though. I can’t think of anything out of the box. So, your metadata should match your deployment, and in a default deployment it’s mostly used to validate your signatures.
Take care,
Nate.
On Mar 14, 2016, at 12:59, Karla Borecky <kborecky at smith.edu<mailto:kborecky at smith.edu>> wrote:
(Not encryption, I know that now.) What would someone do if their v3 IdP were a new addition to InCommon?
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160314/c199e5ab/attachment-0001.html>
More information about the users
mailing list