<HTML><HEAD>
<META content="text/html; charset=utf-8" http-equiv=Content-Type>
<META name=GENERATOR content="MSHTML 9.00.8112.16447"></HEAD>
<BODY style="MARGIN: 4px 4px 1px; FONT: 10pt Segoe UI">
<DIV>Hello Scott </DIV>
<DIV> </DIV>
<DIV>Thanks for your explanation. I have a few follow-up questions:</DIV>
<DIV> </DIV>
<DIV>When the certificate in the metadata file expires, then I should not make changes within the relying-party file to reflect the renewed cert?</DIV>
<DIV> </DIV>
<DIV>As you stated when you renewed the certificate, you don't have to change the key in the relying-party file, but the SP gets a different certificate than the one in the metadata if the key isn't also renewed, correct?</DIV>
<DIV> </DIV>
<DIV>When would I need to update the key and the certificate in the relying-party file?</DIV>
<DIV> </DIV>
<DIV>And what certificate should be in the metadata file? The CA signed certificate or the server issued certificate being referenced in the relying-party file?</DIV>
<DIV> </DIV>
<DIV>Thanks again</DIV>
<DIV>Wavyne Belance<BR><BR>>>> "Cantor, Scott" <cantor.2@osu.edu> 9/11/2012 8:52 AM >>><BR>On 9/11/12 7:29 AM, "Wavyne Belance" <wbelance@luc.edu> wrote:<BR>><BR>>The certificate is updated in my metadata and its location and the key<BR>>are in the relying-party.xml file. I also see the saml2 assertion being<BR>>sent with the correct certificate when I turn debugging on. Where did I<BR>>go wrong?<BR><BR>You're using the wrong key, the metadata's wrong, or the SP doesn't have<BR>the metadata you think it does.<BR><BR>>Are there step by step guides to renewing the Shibboleth certificate?<BR><BR>Several. But renewing a certificate is mostly irrelevant and won't cause<BR>this error. Changing a key is the only time it matters. Renewal does not<BR>involve changing a key.<BR><BR>If you really changed the key, then you would need to follow something<BR>along the lines of <BR><A href="https://wiki.shibboleth.net/confluence/display/SHIB2/IdPKeyRollover">https://wiki.shibboleth.net/confluence/display/SHIB2/IdPKeyRollover</A><BR><BR>-- Scott<BR><BR><BR>--<BR>To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<BR></DIV></BODY></HTML>