Multiple saml cert for same SP
Zico
mailzico at gmail.com
Thu Sep 7 09:17:46 EDT 2017
Thanks much Peter and Alan for your guidance.
Seems like as vendor; I have nothing to do from IDP side to participate in
key rollover operation ( for any SP ).
But.. a quick question....
Say... I configured one SP five years back whose metadata containing a 5
year valid cert and this cert is going to expire tomorrow.
Now, if they push 2nd cert in their SP metadata ( by using SP Key rollover
configuration ).... don't I need to do anything at all from IDP side?
Because... as IDP... that new / 2nd cert is unknown to me.
I know I can update/refresh their metadata "manually" tomorrow to grab new
cert but that might take 10 mins; what end user is trying to achieve a zero
downtime.
On Thu, Sep 7, 2017 at 7:34 AM, Alan Buxey <alan.buxey at myunidays.com> wrote:
> clearly documented (along with the Shibboleth method).
>
> https://spaces.internet2.edu/display/InCFederation/SP+Cert+Migration
>
> (note that InCommon method slightly differs to the Shibboleth method
> since it avoids having 2 certs present..... not an issue for
> shibboleth...and issue for
> other SAML implementations so InCommon take that into consideration)
>
> alan
>
>
> On 7 September 2017 at 12:52, Zico <mailzico at gmail.com> wrote:
> >
> >
> > On Thu, Sep 7, 2017 at 6:45 AM, Peter Schober <
> peter.schober at univie.ac.at>
> > wrote:
> >>
> >> * Zico <mailzico at gmail.com> [2017-09-07 13:26]:
> >> > If any SP has two SAML certificates in it's metadata, can Shib IdP
> >> > support
> >> > that?
> >>
> >> Yes.
> >
> >
> > Very nice!!! Any doc or something like that?
> >
> >
> >>
> >>
> >> > What I am asking is more like how Incommon handles cert
> >> > migration.... keep existing soon-to-be-expired cert in
> >> > metadata... add new metadata.... so there are two metadata
> >> > available. When old cert is expired; there is no outage as new cert
> >> > is already being used there.
> >>
> >> Yes. Check the extensive InCommon documentation on key rollover if
> >> you're an InCommon participant.
> >
> >
> > I am not InCommon participant personally but I'll check how to do 'key
> > rollover in Shibboleth IDP' if there is any.
> >
> >
> >>
> >>
> >> -peter
> >> --
> >> To unsubscribe from this list send an email to
> >> users-unsubscribe at shibboleth.net
> >
> >
> >
> >
> > --
> > Best,
> > Zico
> >
> > --
> > To unsubscribe from this list send an email to
> > users-unsubscribe at shibboleth.net
>
>
>
> --
> Alan Buxey
> Senior Verification Engineer
>
>
>
> UNiDAYS
> The world’s leading Student Affinity Network
>
> Visit myunidays.com
> Find us on Facebook
> Learn more on our corporate site
>
> UNiDAYS can verify 70% of the world's 200 million students across 32
> countries
>
>
>
> This email and any files transmitted with or attached to it contain
> information which is private, confidential and privileged. This
> information is intended solely for the use of the intended recipient
> to whom it is addressed. If you are not the intended recipient, you
> are hereby notified that any disclosure, copying, distribution, or
> the taking of any action in reliance on the contents of this
> electronic transmission is strictly prohibited, and that the
> information should be returned to MyUnidays Limited immediately. If
> you have received this email in error please notify the sender
> immediately and permanently delete the original and any copies of this
> email and any attachments thereto. Thank you.
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
--
Best,
Zico
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170907/5c900b4a/attachment-0001.html>
More information about the users
mailing list