Shib IdP v3: Which certificate do you upload to InCommon?
Karla Borecky
kborecky at smith.edu
Tue Mar 15 10:40:31 EDT 2016
Well, I didn't have any choice in this. I didn't make the decisions on how
to do the upgrade/new v3 installation. I only implemented it once it was up
and running. So, nothing I can do about it, unfortunately. The horse ran
out of the barn before I even knew anyone was near the doors.
On Mon, Mar 14, 2016 at 5:59 PM, Tom Scavo <trscavo at gmail.com> wrote:
> On Mon, Mar 14, 2016 at 2:59 PM, Karla Borecky <kborecky at smith.edu> wrote:
> >
> > So, the question remains: which one should I use?
>
> Did you read the SecurityAndNetworking topic Scott referred to?
>
> https://wiki.shibboleth.net/confluence/x/VoEOAQ
>
> All deployers should read this topic carefully.
>
> > (Not encryption, I know that now.) What
> > would someone do if their v3 IdP were a new addition to InCommon?
>
> If you follow the advice on the above wiki page, you would register
> one cert for SAML message signing and one cert for back-channel TLS.
> However, a new IdP would be advised not to expose back-channel
> endpoints and therefore only one cert would be necessary.
>
> For IdPs that are upgrading to Shib IdP V3 from V2, our advice is
> totally different: https://spaces.internet2.edu/x/GYtHBQ
>
> Tom
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
--
Karla Borecky
Systems Administrator
ITS
Smith College
Northampton, MA 01063
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160315/13a3c465/attachment.html>
More information about the users
mailing list