[External] Re: Recommended or "Best" Practices for Shibboleth IdP?

Cantor, Scott cantor.2 at osu.edu
Fri Oct 2 15:40:48 UTC 2020


On 10/2/20, 11:03 AM, "users on behalf of Shweta Kautia" <users-bounces at shibboleth.net on behalf of skautia at northcarolina.edu> wrote:

>    And I'll just add to that scenario.. we are currently dealing with a vendor that is charging $ to add a signing certificate
> for existing SSO implementations.

I really don't understand what that means. If they're charging you because you wanted them to start allowing for a second signing key from your IdP, then that's nuts, but ultimately scuzzy vendors gonna scuz.

Most vendors can't actually even handle a second signing key so any key change requires a scheduled switch.

But during my key change I certainly never encountered a single vendor wanting to charge for the change.

-- Scott




More information about the users mailing list