Shibboleth IDP ssl certificate not allowing to me to rotate to a new ssl cert
Rod Widdowson
rdw at steadingsoftware.com
Sun May 29 10:34:30 UTC 2022
> . I had a test run on my production clone using the new .pfx certificate and it loaded fine after a service restart.
So the process works..
> I still see in the "jetty.log" file that jetty is still pulling the old cert file somehow. Looking for any ideas that may help
kick jetty off of using that old certificate.
Nothing spring to mind except the obvious that your production machine isn't running the configuration you think it is (but you knew
that).
My go-to tool for this sort of thing is SysInternals procmon, but that gives you a great deal of data to plow through. So I'd start
by comparing the settings for shibd (shibd_idpw) on both systems. Then a tree compare of both the \pf86\Shibboleth\Jetty and
\pf86\Shibboleth\idp\jetty-base directories would be useful.
Rod
More information about the users
mailing list