Notice from Adobe about IdP SHA-1 certificates
Cantor, Scott
cantor.2 at osu.edu
Tue Jul 21 13:04:44 UTC 2020
On 7/21/20, 8:51 AM, "users on behalf of Joseph Fischetti" <users-bounces at shibboleth.net on behalf of Joseph.Fischetti at marist.edu> wrote:
> In following their instructions to correct the issue, you must add an additional IdP to your existing directory. I added a
> new one and didn't configure anything (so there's 2 "SAML Providers" listed. The old one is active, the new one has no
> metadata associated with it). The old one says "Certificate type SHA-1" and "Creation Date - Before April 15, 2020". The
> new one says "Certificate Type SHA-256" and "Creation Date - July 15, 2020".
I just looked at the console to refresh my memory, and yes, that's the terminology they use in ours, when I migrated from the Okta SP to the new one. It showed up as "adding an IdP" even though what was really going on was an SP migration. That doesn't exactly help the clarity.
In effect, they changed things so that adding an IdP also migrated to a new SP at a certain point, and I concluded that the SHA-1 reference was something to do with the older one. The IdP cert they had on file for the "old" one that was reporting itself as SHA-1 simply isn't SHA-1, it was a SHA-2 cert because that's all I had.
I think it's pretty clear that the email is simply wrong.
-- Scott
More information about the users
mailing list