Multiple saml cert for same SP

Zico mailzico at gmail.com
Thu Sep 7 07:51:14 EDT 2017


Oh yes... my mistake, sorry.

Add 'second cert' in running metadata ( one metadata ). :-)

On Thu, Sep 7, 2017 at 6:48 AM, Peter Schober <peter.schober at univie.ac.at>
wrote:

> * Zico <mailzico at gmail.com> [2017-09-07 13:26]:
> > What I am asking is more like how Incommon handles cert
> > migration.... keep existing soon-to-be-expired cert in
> > metadata... add new metadata.... so there are two metadata
> > available. When old cert is expired; there is no outage as new cert
> > is already being used there.
>
> Well, no. Not "add new metadata" but "add new cert *to* metadata".
> Only "one metadata" [document] is available, not two, but that one
> metadata document has two (or more) keys in it.
> -peter
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>



-- 
Best,
Zico
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170907/a54c66df/attachment.html>


More information about the users mailing list