SHib 3.2.1
Tom Scavo
trscavo at gmail.com
Wed Nov 29 09:35:06 EST 2017
On Wed, Nov 29, 2017 at 9:22 AM, Cheltenham, Chris
<ccheltenham-ext at philasd.org> wrote:
>
> Does anyone know why there are multiple certificates in our metadata?
Who knows? They are probably left over from incomplete or failed key
rollover attempts.
> There are 5 to be exact
You don't need that many in any case.
> They are all labeled key descriptor.
>
> <KeyDescriptor use="signing">
The first thing you need to do is determine which of the certificates
in metadata correspond to your private SAML signing key. The rest are
superfluous (assuming your SP partners have the most recent copy of
your metadata).
Is there some reason why your metadata is not published in InCommon?
That would help prevent the situation you're in.
You should start by reading section "Keys and Certificates" in this wiki page:
SecurityAndNetworking
https://wiki.shibboleth.net/confluence/x/VoEOAQ
HTH,
Tom
More information about the users
mailing list