[External] Re: Recommended or "Best" Practices for Shibboleth IdP?

Shweta Kautia skautia at northcarolina.edu
Fri Oct 2 15:42:57 UTC 2020


I apologize -- i meant the vendor's own signing certificate for signed authentication requests.

We don't yet know what the IDP certificate update cost might be at the vendor side.. I'm going to find out.
________________________________
From: users <users-bounces at shibboleth.net> on behalf of Cantor, Scott <cantor.2 at osu.edu>
Sent: Friday, October 2, 2020 11:40 AM
To: Shib Users <users at shibboleth.net>
Subject: Re: [External] Re: Recommended or "Best" Practices for Shibboleth IdP?

On 10/2/20, 11:03 AM, "users on behalf of Shweta Kautia" <users-bounces at shibboleth.net on behalf of skautia at northcarolina.edu> wrote:

>    And I'll just add to that scenario.. we are currently dealing with a vendor that is charging $ to add a signing certificate
> for existing SSO implementations.

I really don't understand what that means. If they're charging you because you wanted them to start allowing for a second signing key from your IdP, then that's nuts, but ultimately scuzzy vendors gonna scuz.

Most vendors can't actually even handle a second signing key so any key change requires a scheduled switch.

But during my key change I certainly never encountered a single vendor wanting to charge for the change.

-- Scott


--
For Consortium Member technical support, see https://wiki.shibboleth.net/confluence/x/coFAAg
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20201002/885062b4/attachment.htm>


More information about the users mailing list