Metadata keys roll over
Aaron Howell
aaron.howell at deakin.edu.au
Thu Jun 14 01:16:13 EDT 2018
Hi,
We are looking to upgrade our keys after many years - we have started to get “don’t support SHA1” conversations. So if we are gong to have to put in new keys, would prefer to make them the default moving forward.
There does not appear to be any clear instruction documented - and most I have found only appear to deal with the Signing key.
Here’s the process for each I have come up with (obviously I understand there are various amounts of lengthy time between some steps):
* Update config with new encryption key as primary, legacy key as secondary
* Update metadata with new encryption certificate as primary certificate
* Update metadata with new signing certificate as secondary certificate
* Publish metadata to SPs
* Update config with new signing key as the default
* Remove legacy certificates from metadata
* Publish metadata to SPs (optional)
* Remove legacy certificates from config
Does that seem like the right process? Is there a wiki page I haven’t be able to locate? Anyone else attempted this? Is it as fun as it sounds?
Cheers,
Aaron
Important Notice: The contents of this email are intended solely for the named addressee and are confidential; any unauthorised use, reproduction or storage of the contents is expressly prohibited. If you have received this email in error, please delete it and any attachments immediately and advise the sender by return email or telephone.
Deakin University does not warrant that this email and any attachments are error or virus free.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20180614/fe9f2149/attachment.html>
More information about the users
mailing list