Metadata certificate on idp.testshib.org seems expired on August 2016
Klingenstein, Nate
nklingenstein at calstate.edu
Tue Nov 15 15:01:03 EST 2016
I believe the original poster just saw an old certificate in metadata which
was commented out entirely. I've removed the commented out certificate.
The uncommented one expires in 2036, and the older signing certificate
would have expired in 2032.
Issuer: CN=idp.testshib.org
Validity
Not Before: Aug 23 21:20:54 2016 GMT
Not After : Aug 23 21:20:54 2036 GMT
This is the only change I made. Nobody should notice any operational difference at all.
> On Nov 15, 2016, at 6:17 AM, Peter Schober <peter.schober at univie.ac.at> wrote:
>
> * Klingenstein, Nate <nklingenstein at calstate.edu> [2016-11-15 05:46]:
>> I guess a certificate can't get any worse than "expired". Software
>> that would break is broken. So, as long as I can re-use the keys, I
>> won't bother with a rollover process.
>
> ACK. There's a middle ground (implemetations that don't care about
> expiration, but reference the certificate itself or its fingerprint --
> like SimpleSAMphp did until recently -- both would change even when
> re-wrapping the same key), but "test" in the name TestShib should mean
> something and people relying on that "service" for more than tests
> (which could break any time) are in for a reminder anyway.
> -peter
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list