Shibboleth IDP ssl certificate not allowing to me to rotate to a new ssl cert

Rod Widdowson rdw at steadingsoftware.com
Sun May 29 10:34:30 UTC 2022


> . I had a test run on my production clone using the new .pfx certificate and it loaded fine after a service restart.

So the process works..

> I still see in the "jetty.log" file that jetty is still pulling the old cert file somehow. Looking for any ideas that may help
kick jetty off of using that old certificate. 

Nothing spring to mind except the obvious that your production machine isn't running the configuration you think it is (but you knew
that).

My go-to tool for this sort of thing is SysInternals procmon, but that gives you a great deal of data to plow through.  So I'd start
by comparing the settings for shibd (shibd_idpw) on both systems.  Then a tree compare of both the \pf86\Shibboleth\Jetty and
\pf86\Shibboleth\idp\jetty-base directories would be useful.

Rod



More information about the users mailing list