IdP signing cert update
Spencer Thomas
Spencer.Thomas at ithaka.org
Fri Oct 2 16:19:11 UTC 2020
We had an incident recently where an IdP updated their signing cert (because it had expired). They lost the ability to log in for a few days, presumably because of the delays in
1. Federation updating their metadata aggregate and
2. Our SP pulling the updated metadata from the federation.
By the time we got the support ticket, the issue had actually self-resolved. But in the process of diagnosing the issue, I noticed that their new signing certificate expires in a year. I have the feeling we’re going to see the same problem with them again next year. And I recall Scott making a comment about how key roll-over is painful. Do I understand correctly that there is not a way to roll over keys without having an “outage” of this sort?
--
Spencer Thomas
Technical Architect / JSTOR and Artstor
ITHAKA<https://www.ithaka.org/> / 301 E. Liberty St, Suite 250, Ann Arbor, MI 48104
Email: Spencer.Thomas at ithaka.org<mailto:Spencer.Thomas at ithaka.org>
Voicemail: 734-887-7004
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20201002/b4136c7b/attachment.htm>
More information about the users
mailing list