SP certificate rollover
Etienne Dysli-Metref
etienne.dysli-metref at switch.ch
Wed Mar 8 03:57:00 EST 2017
On 07/03/17 17:27, Cantor, Scott wrote:
> Even that can cause problems. The problem is that the SP tries to use
> those keys to match credentials it sees in a KeyInfo hint, and when
> things don't match it can incorrectly skip trying a key. That's why I
> advise against all of that, it was an idea that didn't really work
> out well. Using comments is usually a better choice.
Thanks for the insight. :) We're going to remove
`CredentialResolver at keyName` attributes from our SP guides and templates.
Would avoiding key names be something to recommend in Kantara's
federation interop profile? [1]
Etienne
[1] https://kantarainitiative.github.io/SAMLprofiles/fedinterop.html
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 819 bytes
Desc: OpenPGP digital signature
URL: <http://shibboleth.net/pipermail/users/attachments/20170308/4601d989/attachment-0001.sig>
More information about the users
mailing list