Upgrading IDP by Changing SingleSignOnService Locations and Certificates at the Same Time

Peter Schober peter.schober at univie.ac.at
Tue Dec 19 15:03:39 EST 2017


* Albert Luo <albert.uwin at gmail.com> [2017-12-19 20:53]:
> In this scenario,  we will not need certificate roll over. Assuming
> IDP B is configured correctly, SPs will switch to IDP B peacefully.

Well, there's the possibility that an SP sends a SAML protocol message
to one of the old IDP's endpoints, and sees updated metadata for that
IDP (i.e., then having only the new IDP's keys) before it evaluated
the reponse from the old IDP.

So it seems to me you need at least one key rollover, e.g., to
introduce the new IDP's signing key into currently published metadata
(additionally). Once that's propagated all SPs will be able to verify
signatures from either IDP, before, during and after the transition.

-peter


More information about the users mailing list