multiple signing certs for SP

IAM David Bantz dabantz at alaska.edu
Thu Sep 22 14:53:55 EDT 2016


A vended SP is upgrading their signing cert to one signed with
sha512WithRSAEncryption . Adding the new cert as a second signing cert into
their SP metadata seems the seamless way to ease the transition, eventually
removing the old SHA1 signed cert after the transition is complete. I'm
assuming/hoping IdP v2 will verify their SAML assertion which ever of the
two certs they use to sign the assertion. Or is this more complex than I've
assumed?

David Bantz
U Alaska
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160922/4d4e9c6a/attachment.html>


More information about the users mailing list