Multiple saml cert for same SP

Tom Scavo trscavo at gmail.com
Thu Sep 7 09:41:33 EDT 2017


On Thu, Sep 7, 2017 at 9:17 AM, Zico <mailzico at gmail.com> wrote:
>
> Seems like as vendor; I have nothing to do from IDP side to participate in
> key rollover operation ( for any SP ).

Just a bit of advice. Ask more precise questions. Key rollover is one
of those things where the details matter.

It's not clear from what you've said whether you control the IdP
metadata, the SP metadata, or both. Also, if you are an InCommon
participant, that matters greatly since there are constraints for
which you have no control. Read the InCommon documentation. (I wrote
it, so I know it's correct :)

It matters if the <md:KeyDescriptor> element has a 'use' XML
attribute. If it doesn't (or can't), rollover is more difficult. In
that case, you should precisely follow the documentation.

The case use="signing" is completely different than the case
use="encryption". You need to wrap those concepts around your head.
Don't begin the key rollover process until you understand the
difference between signing and encryption.

Just my two cents.

Tom


More information about the users mailing list