IdP signing cert update

Cantor, Scott cantor.2 at osu.edu
Fri Oct 2 17:39:26 UTC 2020


On 10/2/20, 1:27 PM, "users on behalf of Spencer Thomas" <users-bounces at shibboleth.net on behalf of Spencer.Thomas at ithaka.org> wrote:

>    Ah, the "certificate" expiration date for the signing key is actually irrelevant to the SP?

To a Shibboleth SP, yes, because that's what the only standard for using metadata says.

>  The attributes for their new key cert are (below) which suggests that maybe ADFS had an issue with it? 

ADFS is broken in many ways, and that's one of them.

-- Scott




More information about the users mailing list