Impact of Reduced TLS Certificate Lifetimes on CA-Signed SAML Certificates
Wei Dai
Wei.Dai at Clarivate.com
Fri May 23 14:44:02 UTC 2025
Thanks for the information and comments. They were very helpful!
I'm asking from an SP perspective, as we are occasionally requested by customers to issue SP certificates following their policies. I would appreciate your advice on two other certificate-related issues (please let me know if it's better to start new threads for them):
As mentioned in the document below, a German federation has started requiring SAML certificates with a 3072-bit RSA key. Are any other federations or institutions planning to implement this policy? Any comments? https://doku.tid.dfn.de/de:certificates
Regarding using a long-term certificate, what's the recommended period and is there a standard? The default Microsoft Entry ID IdP certificate is valid for 3 years, while another major IdP vendor issues a 10-year certificate.
Wei
Confidentiality note: This e-mail may contain confidential information from Clarivate. If you are not the intended recipient, be aware that any disclosure, copying, distribution or use of the contents of this e-mail is strictly prohibited. If you have received this e-mail in error, please delete this e-mail and notify the sender as soon as possible.
More information about the users
mailing list