<html><body><div style="color:#000; background-color:#fff; font-family:arial, helvetica, sans-serif;font-size:12pt"><div><span>OK, I have made all of my changes on the SP side and am now ready to get the new cert published in the InCommon Metadata.</span></div><div><br><span></span></div><div><span>The instructions say that when I add my cert to InCommon I need to add it with no use= XML attrib. But in the dropdown I have Signing only and Signing and Encryption. Which of these should be selected for both the NEW and the OLD certs?</span></div><div><br></div><div style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><div style="font-family: times new roman, new york, times, serif; font-size: 12pt;"><font size="2" face="Arial"><hr size="1"><b><span style="font-weight:bold;">From:</span></b> Mike Flynn <shibbolethlynda@yahoo.com><br><b><span style="font-weight: bold;">To:</span></b> Shib Users
<users@shibboleth.net><br><b><span style="font-weight: bold;">Sent:</span></b> Friday, October 21, 2011 9:22 AM<br><b><span style="font-weight: bold;">Subject:</span></b> Re: Cert rollover sanity check<br></font><br>
<div id="yiv990023556"><div><div style="color:#000;background-color:#fff;font-family:arial, helvetica, sans-serif;font-size:12pt;"><div><span>Thanks, Tom. You're not as bad as Max says after all :D</span></div><div><br></div><div style="font-family:arial, helvetica, sans-serif;font-size:12pt;"><div style="font-family:times new roman, new york, times, serif;font-size:12pt;"><font size="2" face="Arial"><hr size="1"><b><span style="font-weight:bold;">From:</span></b> Tom Scavo <trscavo@gmail.com><br><b><span style="font-weight:bold;">To:</span></b> Shib Users <users@shibboleth.net><br><b><span style="font-weight:bold;">Sent:</span></b> Friday, October 21, 2011 8:42 AM<br><b><span style="font-weight:bold;">Subject:</span></b> Re: Cert rollover sanity check<br></font><br>
On Fri, Oct 21, 2011 at 10:56 AM, Mike Flynn <<a rel="nofollow" ymailto="mailto:shibbolethlynda@yahoo.com" target="_blank" href="mailto:shibbolethlynda@yahoo.com">shibbolethlynda@yahoo.com</a>> wrote:<br>> ... my step 2 will look like this:<br>> Change old setting FROM:<br>><br>> <!-- Your SP generated these credentials. They're used to talk to<br>> IdP's. --><br>> <CredentialResolver type="File" key="sp-key.pem"<br>> certificate="sp-cert.pem"/><br>><br>> TO:<br>><br>> <CredentialResolver type="Chaining"><br>> <!--<br>> Certificate/Private key pairs are
read in sequence.<br>>
Unless specificially defined only the first<br>> CredentialResolver is used for attribute requests.<br>> --><br>> <CredentialResolver type="File" keyName="Standby"<br>> use="encryption"<br>><br>> key="C:\opt\shibboleth-sp\etc\shibboleth\sp-key-2011.pem"<br>><br>> certificate="C:\opt\shibboleth-sp\etc\shibboleth\sp-cert-2011.pem"/><br>> <CredentialResolver type="File" keyName="Active"<br>><br>> key="C:\opt\shibboleth-sp\etc\shibboleth\sp-key.pem"<br>><br>> certificate="C:\opt\shibboleth-sp\etc\shibboleth\sp-cert.pem"/><br>>
</CredentialResolver><br>><br>> That about right?<br><br>Yup!<br><br>Good luck,<br>Tom<br>--<br>To unsubscribe from this list send an email to <a rel="nofollow" ymailto="mailto:users-unsubscribe@shibboleth.net" target="_blank" href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br><br><br></div></div></div></div></div><br>--<br>To unsubscribe from this list send an email to <a ymailto="mailto:users-unsubscribe@shibboleth.net" href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br><br></div></div></div></body></html>