Multiple saml cert for same SP
Zico
mailzico at gmail.com
Thu Sep 7 07:52:54 EDT 2017
On Thu, Sep 7, 2017 at 6:45 AM, Peter Schober <peter.schober at univie.ac.at>
wrote:
> * Zico <mailzico at gmail.com> [2017-09-07 13:26]:
> > If any SP has two SAML certificates in it's metadata, can Shib IdP
> support
> > that?
>
> Yes.
>
Very nice!!! Any doc or something like that?
>
> > What I am asking is more like how Incommon handles cert
> > migration.... keep existing soon-to-be-expired cert in
> > metadata... add new metadata.... so there are two metadata
> > available. When old cert is expired; there is no outage as new cert
> > is already being used there.
>
> Yes. Check the extensive InCommon documentation on key rollover if
> you're an InCommon participant.
>
I am not InCommon participant personally but I'll check how to do 'key
rollover in Shibboleth IDP' if there is any.
>
> -peter
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
--
Best,
Zico
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170907/541cc132/attachment.html>
More information about the users
mailing list