Multiple saml cert for same SP

Zico mailzico at gmail.com
Sun Sep 10 15:28:38 EDT 2017


Thanks much for your help, Everyone.
I tried the whole situation locally and Shib IDP server indeed can handle
the situation without any downtime.

- Configured Shibboleth SP with two certs ( first one with 1 year validity
and second cert with 1 day validity ).
  - By adding type == chaining in CredentialResolver snippet in
shibboleth2.xml
- Used SP's metadata ( which has two certs inside of it ) to create trust
relationship here in IdP.
- 1 day valid cert expired today and there isn't issue in SSO.

Peter, I am sorry that I didn't mention about technical specification
earlier.
I am using Gluu server.

- Gluu Server v2 ( shibboleth v2 included ) is auto reloading configuration
in 5 mins interval.
- Gluu Server v3 ( shibboleth v3 included ) is auto reloading every min.

On Thu, Sep 7, 2017 at 10:08 AM, Peter Schober <peter.schober at univie.ac.at>
wrote:

> * Zico <mailzico at gmail.com> [2017-09-07 15:18]:
> > Seems like as vendor; I have nothing to do from IDP side to
> > participate in key rollover operation ( for any SP ).
>
> I can't speak to any SAML implementation you may use (and you don't
> say) but at least when using the Shibboleth IDP there's nothing to do
> about SP key rollover -- which of course is the whole point of doing
> the steps of a key rollover properly.
>
> > Say... I configured one SP five years back whose metadata containing
> > a 5 year valid cert and this cert is going to expire tomorrow.
>
> Both the Shibboleth IDP and the SP support the
> "SAML V2.0 Metadata Interoperability Profile" out of the box:
> https://wiki.oasis-open.org/security/SAML2MetadataIOP
> As such certificate expiration (among other things) does not factor
> into the trustworthiness of a certificate at all.
>
> If you're using another software and/or a different trust model
> that may not be the case for you.
>
> You don't give any specifics, which is why you get <n> different
> answers.
>
> > I know I can update/refresh their metadata "manually" tomorrow to
> > grab new cert but that might take 10 mins; what end user is trying
> > to achieve a zero downtime.
>
> Are you saying you are using the Shibboleth IDP v3.3.x and
> reload-metadata.sh takes 10 minutes in your deployment?
> You'll have to provide more specifics if you want help with that.
>
> If you're not doing that then you're probably just Doing It Wrong™.
> Again, you don't mention technical details, so it's impossible to know
> or advise.
> -peter
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>



-- 
Best,
Zico
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170910/dafb01a3/attachment.html>


More information about the users mailing list