Shib IdP v3: Which certificate do you upload to InCommon?

Tom Scavo trscavo at gmail.com
Mon Mar 14 17:59:14 EDT 2016


On Mon, Mar 14, 2016 at 2:59 PM, Karla Borecky <kborecky at smith.edu> wrote:
>
> So, the question remains: which one should I use?

Did you read the SecurityAndNetworking topic Scott referred to?

https://wiki.shibboleth.net/confluence/x/VoEOAQ

All deployers should read this topic carefully.

> (Not encryption, I know that now.) What
> would someone do if their v3 IdP were a new addition to InCommon?

If you follow the advice on the above wiki page, you would register
one cert for SAML message signing and one cert for back-channel TLS.
However, a new IdP would be advised not to expose back-channel
endpoints and therefore only one cert would be necessary.

For IdPs that are upgrading to Shib IdP V3 from V2, our advice is
totally different: https://spaces.internet2.edu/x/GYtHBQ

Tom


More information about the users mailing list