IDP with multiple cert

Zico mailzico at gmail.com
Fri Feb 24 04:06:06 UTC 2023


Hello,

I would like to get some idea if it's possible to have my IDP with multiple
cert?
Meaning... it's more like federation metadata but there will be just two
sets of idp-signing and idp-encryption keys in my metadata.

Reason behind this request: I would like to give my customers little
comfort when it's IDP's cert renewal ( shibboleth cert and key ) time.
Right now they need to call a downtime and need concrete real time
communication with all affiliated SPs when IDP renew their cert.

Instead I was thinking like what if I could allow them to have two sets of
cert ( one set is that which is going to expire and another one is renewed
one ). In that way... they could only inform SPs to refresh IDP's metadata
and there won't be any downtime as well; because expired cert and renewed
cert both are in the same metadata.

-- 
Best,
Zico
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20230224/e3a59094/attachment.htm>


More information about the users mailing list