multiple signing certs for SP
IAM David Bantz
dabantz at alaska.edu
Thu Sep 22 14:53:55 EDT 2016
A vended SP is upgrading their signing cert to one signed with
sha512WithRSAEncryption . Adding the new cert as a second signing cert into
their SP metadata seems the seamless way to ease the transition, eventually
removing the old SHA1 signed cert after the transition is complete. I'm
assuming/hoping IdP v2 will verify their SAML assertion which ever of the
two certs they use to sign the assertion. Or is this more complex than I've
assumed?
David Bantz
U Alaska
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160922/4d4e9c6a/attachment.html>
More information about the users
mailing list