multiple signing certs for SP

Cantor, Scott cantor.2 at osu.edu
Thu Sep 22 15:09:15 EDT 2016


> A vended SP is upgrading their signing cert to one signed with
> sha512WithRSAEncryption . Adding the new cert as a second signing cert into
> their SP metadata seems the seamless way to ease the transition, eventually
> removing the old SHA1 signed cert after the transition is complete. I'm
> assuming/hoping IdP v2 will verify their SAML assertion which ever of the
> two certs they use to sign the assertion. Or is this more complex than I've
> assumed?

That's how it works, but it is much more complex than that because you're ignoring encryption. I don't know if you're talking about a signing key or a dual use key being used to encrypt data under. Both cases are discussed at length in the wiki and I think InCommon has additional material on it.
 
-- Scott



More information about the users mailing list