IdP assertions encryption issue

Cantor, Scott cantor.2 at osu.edu
Wed Jan 31 12:29:26 EST 2018


On 1/31/18, 11:37 AM, "users on behalf of Guillaume Rousse" <users-bounces at shibboleth.net on behalf of guillaume.rousse at renater.fr> wrote:

>  Basically, when the same certificate/key pair is used both for 
> encryption and signature, you can't satisfy both migration constraints 
> at once (publishing before using for signature, using before publishing 
> for encryption).

And you don't have to, as that wiki page demonstrates. It is perfectly possible to migrate one key used for both. That doesn't mean it's optimal, and what should be done now probably is just forgo signing entirely, which the SP generally doesn't need to do, and focus on encryption/decryption.

-- Scott




More information about the users mailing list