Question about relying-party-system.xml
Cantor, Scott
cantor.2 at osu.edu
Wed Jun 30 18:36:24 UTC 2021
On 6/30/21, 2:20 PM, "users on behalf of Ullfig, Roberto Alfredo" <users-bounces at shibboleth.net on behalf of rullfig at uic.edu> wrote:
> Thanks! Are there any potential issues with switching from a SHA1 signing certificate to a SHA 256 signing
> certificate? Could any SP be impacted by this?
Yes, not because it's a SHA-2 certificate but because you're *changing your certificate*. That is going to break a ton of stuff.
If it's not Shibboleth, there is no standard governing its behavior and no documentation as to how it does what it does.
So the answer is that you cannot hope to predict anything about it, which is why key changes are so painful. There are a huge number of systems that treat a certificate change as equivalent to a key change. Shibboleth just doesn’t happen to be one of them.
-- Scott
More information about the users
mailing list