Shib IdP v3: Which certificate do you upload to InCommon?
Tom Scavo
trscavo at gmail.com
Mon Mar 14 17:59:14 EDT 2016
On Mon, Mar 14, 2016 at 2:59 PM, Karla Borecky <kborecky at smith.edu> wrote:
>
> So, the question remains: which one should I use?
Did you read the SecurityAndNetworking topic Scott referred to?
https://wiki.shibboleth.net/confluence/x/VoEOAQ
All deployers should read this topic carefully.
> (Not encryption, I know that now.) What
> would someone do if their v3 IdP were a new addition to InCommon?
If you follow the advice on the above wiki page, you would register
one cert for SAML message signing and one cert for back-channel TLS.
However, a new IdP would be advised not to expose back-channel
endpoints and therefore only one cert would be necessary.
For IdPs that are upgrading to Shib IdP V3 from V2, our advice is
totally different: https://spaces.internet2.edu/x/GYtHBQ
Tom
More information about the users
mailing list