Shib IdP v3: Which certificate do you upload to InCommon?
Karla Borecky
kborecky at smith.edu
Mon Mar 14 16:41:14 EDT 2016
I'm using the same string to generate that - and it looks the same as on
the old IdP (the eduPersonTargetedID)
On Mon, Mar 14, 2016 at 4:35 PM, Peter Schober <peter.schober at univie.ac.at>
wrote:
> * Cantor, Scott <cantor.2 at osu.edu> [2016-03-14 20:52]:
> > > * Karla Borecky <kborecky at smith.edu> [2016-03-14 20:00]:
> > > > Well, we brought up a new IdP, with new certs and a new entityID.
> > >
> > > Then there's nothing to change wtih regards to your existing/old IDP,
> > > and you register the new IDP with InCommon the same way everyone
> > > registers IDPs with InCommon.
> >
> > I actually overlooked the "new entityID" part. Obviously that's not
> > a key rotation, then, it's just a new IdP entirely. Any SP you're
> > working with is effectively starting from scratch, so there are any
> > number of outside considerations here. They might have to make
> > database changes, or any number of adjustments on their side, for
> > you to completely change to a new IdP.
>
> Including potentially lost access to user data at SPs, due to changed
> persistentIDs / eduPersonTargetedID!
> (Unless you can virtualize the issuer part, and the SP would accept
> that, and the OP actually took care to do all that.)
> -peter
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
--
Karla Borecky
Systems Administrator
ITS
Smith College
Northampton, MA 01063
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160314/f6c212c5/attachment.html>
More information about the users
mailing list