<html><body><div style="color:#000; background-color:#fff; font-family:arial, helvetica, sans-serif;font-size:12pt"><div><span>OK, I have made all of my changes on the SP side and am now ready to get the new cert published in the InCommon Metadata.</span></div><div><br><span></span></div><div><span>The instructions say that when I add my cert to InCommon I need to add it with no use= XML attrib.&nbsp; But in the dropdown I have Signing only and Signing and Encryption.&nbsp; Which of these should be selected for both the NEW and the OLD certs?</span></div><div><br></div><div style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><div style="font-family: times new roman, new york, times, serif; font-size: 12pt;"><font size="2" face="Arial"><hr size="1"><b><span style="font-weight:bold;">From:</span></b> Mike Flynn &lt;shibbolethlynda@yahoo.com&gt;<br><b><span style="font-weight: bold;">To:</span></b> Shib Users
 &lt;users@shibboleth.net&gt;<br><b><span style="font-weight: bold;">Sent:</span></b> Friday, October 21, 2011 9:22 AM<br><b><span style="font-weight: bold;">Subject:</span></b> Re: Cert rollover sanity check<br></font><br>
<div id="yiv990023556"><div><div style="color:#000;background-color:#fff;font-family:arial, helvetica, sans-serif;font-size:12pt;"><div><span>Thanks, Tom.&nbsp; You're not as bad as Max says after all :D</span></div><div><br></div><div style="font-family:arial, helvetica, sans-serif;font-size:12pt;"><div style="font-family:times new roman, new york, times, serif;font-size:12pt;"><font size="2" face="Arial"><hr size="1"><b><span style="font-weight:bold;">From:</span></b> Tom Scavo &lt;trscavo@gmail.com&gt;<br><b><span style="font-weight:bold;">To:</span></b> Shib Users &lt;users@shibboleth.net&gt;<br><b><span style="font-weight:bold;">Sent:</span></b> Friday, October 21, 2011 8:42 AM<br><b><span style="font-weight:bold;">Subject:</span></b> Re: Cert rollover sanity check<br></font><br>
On Fri, Oct 21, 2011 at 10:56 AM, Mike Flynn &lt;<a rel="nofollow" ymailto="mailto:shibbolethlynda@yahoo.com" target="_blank" href="mailto:shibbolethlynda@yahoo.com">shibbolethlynda@yahoo.com</a>&gt; wrote:<br>&gt; ... my step 2 will look like this:<br>&gt; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; Change old setting FROM:<br>&gt;<br>&gt; &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &lt;!-- Your SP generated these credentials.&nbsp; They're used to talk to<br>&gt; IdP's. --&gt;<br>&gt; &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &lt;CredentialResolver type="File" key="sp-key.pem"<br>&gt; certificate="sp-cert.pem"/&gt;<br>&gt;<br>&gt; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; TO:<br>&gt;<br>&gt; &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &lt;CredentialResolver type="Chaining"&gt;<br>&gt; &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &lt;!--<br>&gt; &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Certificate/Private key pairs are
 read in sequence.<br>&gt;
 &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Unless specificially defined only the first<br>&gt; &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; CredentialResolver is used for attribute requests.<br>&gt; &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; --&gt;<br>&gt; &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &lt;CredentialResolver type="File" keyName="Standby"<br>&gt; use="encryption"<br>&gt;<br>&gt; key="C:\opt\shibboleth-sp\etc\shibboleth\sp-key-2011.pem"<br>&gt;<br>&gt; certificate="C:\opt\shibboleth-sp\etc\shibboleth\sp-cert-2011.pem"/&gt;<br>&gt; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&lt;CredentialResolver type="File" keyName="Active"<br>&gt;<br>&gt; key="C:\opt\shibboleth-sp\etc\shibboleth\sp-key.pem"<br>&gt;<br>&gt; certificate="C:\opt\shibboleth-sp\etc\shibboleth\sp-cert.pem"/&gt;<br>&gt; &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
 &lt;/CredentialResolver&gt;<br>&gt;<br>&gt; That about right?<br><br>Yup!<br><br>Good luck,<br>Tom<br>--<br>To unsubscribe from this list send an email to <a rel="nofollow" ymailto="mailto:users-unsubscribe@shibboleth.net" target="_blank" href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br><br><br></div></div></div></div></div><br>--<br>To unsubscribe from this list send an email to <a ymailto="mailto:users-unsubscribe@shibboleth.net" href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br><br></div></div></div></body></html>