Migrating to Relying-Party V3
Cantor, Scott
cantor.2 at osu.edu
Tue Apr 25 12:54:00 EDT 2017
> So the question is: Why did you think you needed to do that? If it's
> because the encryption cred key/cert doesn't exist in credentials/,
> then that implies you have to do something to get the encryption
> key/cert set up, as mentioned in my other reply. Again, not sure
> off-hand what we do on a v2 upgrade.
Now I see the docs.
"As an upgraded V2 IdP will not have credentials suitable for decrypting content sent to the IdP, for now just edit conf/credentials.xml to comment out the encryption credential, as follows:"
That doesn't sound right to me given how the wiring works, so that's probably my error. I'd have to review it, I'm in another head space at the moment. Please file a bug.
For the time being if following the documentation doesn't actually work, the only fix is to generate a new keypair for decryption and get it in place so that step doesn't have to happen.
The OP appears to be the first person to actually follow the upgrade instructions given that it's 2+ years later and nobody has reported it.
-- Scott
More information about the users
mailing list