Shib IdP v3: Which certificate do you upload to InCommon?

Cantor, Scott cantor.2 at osu.edu
Mon Mar 14 15:18:49 EDT 2016


> That's the situation. We only have a couple of SPs that use our InCommon
> metadata, but I need to change it to point to the new one.

Then you need to roll the key. That requires a multi step process. You need to add the new key to the metadata, wait a day at least, then you can switch to the key you added. And that assumes the SPs in question actually use the metadata, which is not something you can know apriori.

> What would someone do if their v3 IdP were a new addition to InCommon?

Presumably they would register the key(s) they'd been using already.

-- Scott



More information about the users mailing list