"no signing credential resolved, leaving message unsigned"
Peter Schober
peter.schober at univie.ac.at
Wed Jun 18 17:45:12 UTC 2025
sacha+shibboleth--- via users <users at shibboleth.net> [2025-06-18 18:43 CEST]:
> Our signing and encryption certificates expired, so the IdP folk asked us to
> replace them. The process was to generate signing and encryption keys, use
> them to generate CSRs, submit them to the IdP people, receive the
> certificates from them, sign and submit a metadata file, then switch things
> over at the IdP and SP ends.
Also note that your "signing and encryption certificates" are used to
secure SAML protocol messages. "sign and submit a metadata file" is a
completely different use case and does not require use of the same
credentials.
In fact if you used signed metadata that's all anyone would ever need
in order to establish the trustworthiness of anything contained in
that metadata, including the certificats / public keys.
That's formally specified in the SAML Standard
"SAML V2.0 Metadata Interoperability Profile"
https://wiki.oasis-open.org/security/SAML2MetadataIOP
Best,
-peter
More information about the users
mailing list