IdP signing cert update
Cantor, Scott
cantor.2 at osu.edu
Fri Oct 2 16:32:29 UTC 2020
On 10/2/20, 12:19 PM, "users on behalf of Spencer Thomas" <users-bounces at shibboleth.net on behalf of Spencer.Thomas at ithaka.org> wrote:
> By the time we got the support ticket, the issue had actually self-resolved. But in the process of diagnosing the issue, I
> noticed that their new signing certificate expires in a year.
Any software that notices is broken. There is no expiration except the metadata itself.
> I have the feeling we’re going to see the same problem with them again next year. And I recall Scott making a comment
> about how key roll-over is painful. Do I understand correctly that there is not a way to roll over keys without having a
> “outage” of this sort?
It is entirely possible and well documented by InCommon, provided the SP is metadata-aware. Rolling signing keys is trivial in a metadata-aware system. Rolling encryption keys is harder.
-- Scott
More information about the users
mailing list