SHib 3.2.1

Tom Scavo trscavo at gmail.com
Wed Nov 29 09:35:06 EST 2017


On Wed, Nov 29, 2017 at 9:22 AM, Cheltenham, Chris
<ccheltenham-ext at philasd.org> wrote:
>
> Does anyone know why there are multiple certificates in our metadata?

Who knows? They are probably left over from incomplete or failed key
rollover attempts.

> There are 5 to be exact

You don't need that many in any case.

> They are all labeled key descriptor.
>
> <KeyDescriptor use="signing">

The first thing you need to do is determine which of the certificates
in metadata correspond to your private SAML signing key. The rest are
superfluous (assuming your SP partners have the most recent copy of
your metadata).

Is there some reason why your metadata is not published in InCommon?
That would help prevent the situation you're in.

You should start by reading section "Keys and Certificates" in this wiki page:

SecurityAndNetworking
https://wiki.shibboleth.net/confluence/x/VoEOAQ

HTH,

Tom


More information about the users mailing list