SP certificate rollover
Cantor, Scott
cantor.2 at osu.edu
Fri Mar 3 09:10:25 EST 2017
On 3/3/17, 9:04 AM, "users on behalf of Tom Scavo" <users-bounces at shibboleth.net on behalf of trscavo at gmail.com> wrote:
> Right, which is why multiple encryption certificates in metadata is not recommended.
As long as the consumer can wield all of them, it's generally fine, and it can be quite complex to pull off "multiple signing keys but just one encryption key" with a lot of federations. Which I imagine relates to the OP's concern. It's very hard to get things to work if there are federations imposing constraints.
-- Scott
More information about the users
mailing list