Multiple saml cert for same SP
Peter Schober
peter.schober at univie.ac.at
Thu Sep 7 11:08:01 EDT 2017
* Zico <mailzico at gmail.com> [2017-09-07 15:18]:
> Seems like as vendor; I have nothing to do from IDP side to
> participate in key rollover operation ( for any SP ).
I can't speak to any SAML implementation you may use (and you don't
say) but at least when using the Shibboleth IDP there's nothing to do
about SP key rollover -- which of course is the whole point of doing
the steps of a key rollover properly.
> Say... I configured one SP five years back whose metadata containing
> a 5 year valid cert and this cert is going to expire tomorrow.
Both the Shibboleth IDP and the SP support the
"SAML V2.0 Metadata Interoperability Profile" out of the box:
https://wiki.oasis-open.org/security/SAML2MetadataIOP
As such certificate expiration (among other things) does not factor
into the trustworthiness of a certificate at all.
If you're using another software and/or a different trust model
that may not be the case for you.
You don't give any specifics, which is why you get <n> different
answers.
> I know I can update/refresh their metadata "manually" tomorrow to
> grab new cert but that might take 10 mins; what end user is trying
> to achieve a zero downtime.
Are you saying you are using the Shibboleth IDP v3.3.x and
reload-metadata.sh takes 10 minutes in your deployment?
You'll have to provide more specifics if you want help with that.
If you're not doing that then you're probably just Doing It Wrong™.
Again, you don't mention technical details, so it's impossible to know
or advise.
-peter
More information about the users
mailing list