Shibboleth Identity Provider Security Advisory [4 October 2017]

Cantor, Scott cantor.2 at osu.edu
Thu Nov 9 15:57:33 EST 2017


> Ok, I think I understand re the root and intermediate certs, but I'm still
> unclear on what happens when the LDAP cert gets updated in the course of
> its normal lifecycle. If this is a dependency that's tightly coupled to
> the IdP's operation what is the best practice or recommendation for
> handling the rollover of the LDAP server's cert?

The BP in my opinion is to use a self-signed certificate, because this isn't a web site. The actual practice is to operate them like web sites, so if you prefer to trust a CA, then you can do that. I do, for the same reason, I have no visibility into them changing the key.

-- Scott



More information about the users mailing list