Notice from Adobe about IdP SHA-1 certificates

Donald Lohr lohrda at jmu.edu
Thu Sep 3 16:06:20 UTC 2020


It seems plausible to me from Adobe's point of view, that in this old 
okta model, okta is its "Identity Provider.

Based on our Shibboleth configuration for Adobe, okta is the SP, as seen 
by the metadata entityID:

https://www.okta.com/saml2/service-provider/..............

So it all depends on where you stand when you announce something is 
deprecated. So I guess one could even argue, that Adobe does not even 
know that my Shibboleth IdP even exist.

Don

On 7/21/20 2:28 PM, Lee Foltz wrote:
> Yesterday I followed these instructions from Abobe and had to Add new 
> IDP, which was just uploading our metadata again, then they provided a 
> link to download or use URL to use Adobe new SP metadata with SHA-256 
> certificate.
> https://helpx.adobe.com/enterprise/using/set-up-identity.html#migrateesaml 
> <https://urldefense.proofpoint.com/v2/url?u=https-3A__helpx.adobe.com_enterprise_using_set-2Dup-2Didentity.html-23migrateesaml&d=DwMFaQ&c=eLbWYnpnzycBCgmb7vCI4uqNEB9RSjOdn_5nBEmmeq0&r=Pa2DB88IW_s2TyLfktHtWA&m=XrDZ92WjqteMdmQTAl8jpmptdljOQmhYgdS8LdXj4M8&s=skrs6JyaDISVRDB8JrV7-2DX-Pa2t5d-tdQWiM1ixFU&e=>
>
> There is also a Test feature to test the new IDP setup with the new 
> Adobe SP metadata, you can also revert changes and roll back to other 
> IDP still configured (SHA-1) if your new setup doesn't work.
> We tested and had no issues with Federated Login on new setup with new 
> Adobe SP metadata.
>
> Hope this helps everyone.
>
> On Tue, Jul 21, 2020 at 9:43 AM Cantor, Scott <cantor.2 at osu.edu 
> <mailto:cantor.2 at osu.edu>> wrote:
>
>     On 7/21/20, 9:38 AM, "users on behalf of Peter Schober"
>     <users-bounces at shibboleth.net
>     <mailto:users-bounces at shibboleth.net> on behalf of
>     peter.schober at univie.ac.at <mailto:peter.schober at univie.ac.at>> wrote:
>
>     >    I'll definitively be keeping a reference to this thread handy
>     as I
>     >    feel I'll be needing it in the coming months.
>
>     This topic comes up nearly every ACAMP with no real solution, but
>     we need some kind of neutral venue for information sharing that we
>     can use to post this sort of knowledge that people will see.
>
>     -- Scott
>
>
>     -- 
>     For Consortium Member technical support, see
>     https://wiki.shibboleth.net/confluence/x/coFAAg
>     <https://urldefense.proofpoint.com/v2/url?u=https-3A__wiki.shibboleth.net_confluence_x_coFAAg&d=DwMFaQ&c=eLbWYnpnzycBCgmb7vCI4uqNEB9RSjOdn_5nBEmmeq0&r=Pa2DB88IW_s2TyLfktHtWA&m=XrDZ92WjqteMdmQTAl8jpmptdljOQmhYgdS8LdXj4M8&s=wxUvGKdwNA72T8Q0NE5MQ9WpPHF_fJwvBJk_aL5mmto&e=>
>     To unsubscribe from this list send an email to
>     users-unsubscribe at shibboleth.net
>     <mailto:users-unsubscribe at shibboleth.net>
>
>
>
> -- 
> Lee Foltz
> Oakland University - UTS
> Senior Identity and Access Management Engineer
> 248-370-2675
>

-- 
D o n a l d   L o h r
I n f o r m a t i o n   S y s t e m s
J a m e s   M a d i s o n   U n i v e r s i t y
5 4 0 . 5 6 8 . 3 7 3 0

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20200903/c0261b81/attachment.htm>


More information about the users mailing list