<html>
  <head>
    <meta content="text/html; charset=ISO-8859-1"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    Hi Wavyne,<br>
    <br>
    if it is of any help - I find the following two pages very useful:<br>
    <p><a
href="https://www.switch.ch/aai/docs/shibboleth/SWITCH/sp-certificate-rollover.html"
        class="external free"
title="https://www.switch.ch/aai/docs/shibboleth/SWITCH/sp-certificate-rollover.html"
        rel="nofollow">https://www.switch.ch/aai/docs/shibboleth/SWITCH/sp-certificate-rollover.html</a>
    </p>
    <p><a
href="https://www.switch.ch/aai/docs/shibboleth/SWITCH/idp-certificate-rollover.html"
        class="external free"
title="https://www.switch.ch/aai/docs/shibboleth/SWITCH/idp-certificate-rollover.html"
        rel="nofollow">https://www.switch.ch/aai/docs/shibboleth/SWITCH/idp-certificate-rollover.html</a><br>
    </p>
    <p>Cheers,<br>
      Martin<br>
    </p>
    <br>
    <div class="moz-cite-prefix">Am 12.09.2012 16:49, schrieb Wavyne
      Belance:<br>
    </div>
    <blockquote
      cite="mid:50505A990200007E000602E4@gwials1.is-svr.luc.edu"
      type="cite">
      <meta content="text/html; charset=ISO-8859-1"
        http-equiv="Content-Type">
      <meta name="GENERATOR" content="MSHTML 9.00.8112.16447">
      <div>Hello Scott </div>
      <div>&nbsp;</div>
      <div>Thanks for your explanation. I have a few follow-up
        questions:</div>
      <div>&nbsp;</div>
      <div>When the certificate&nbsp;in the metadata file expires, then I
        should not make changes within the relying-party file to reflect
        the renewed cert?</div>
      <div>&nbsp;</div>
      <div>As you stated when you renewed&nbsp;the certificate,&nbsp;you don't
        have to change the key in the relying-party file, but the SP
        gets a different certificate than the one in the metadata if the
        key isn't also renewed, correct?</div>
      <div>&nbsp;</div>
      <div>When would I need to update the key and the certificate in
        the relying-party file?</div>
      <div>&nbsp;</div>
      <div>And what certificate should be in the metadata file? The CA
        signed certificate or the server issued certificate
        being&nbsp;referenced in the relying-party file?</div>
      <div>&nbsp;</div>
      <div>Thanks again</div>
      <div>Wavyne Belance<br>
        <br>
        &gt;&gt;&gt; "Cantor, Scott" <a class="moz-txt-link-rfc2396E" href="mailto:cantor.2@osu.edu">&lt;cantor.2@osu.edu&gt;</a> 9/11/2012
        8:52 AM &gt;&gt;&gt;<br>
        On 9/11/12 7:29 AM, "Wavyne Belance" <a class="moz-txt-link-rfc2396E" href="mailto:wbelance@luc.edu">&lt;wbelance@luc.edu&gt;</a>
        wrote:<br>
        &gt;<br>
        &gt;The certificate is updated in my metadata and its location
        and&nbsp; the key<br>
        &gt;are in the relying-party.xml file. I also see the saml2
        assertion being<br>
        &gt;sent with the correct certificate when I turn debugging on.
        Where did I<br>
        &gt;go wrong?<br>
        <br>
        You're using the wrong key, the metadata's wrong, or the SP
        doesn't have<br>
        the metadata you think it does.<br>
        <br>
        &gt;Are there step by step guides to renewing the Shibboleth
        certificate?<br>
        <br>
        Several. But renewing a certificate is mostly irrelevant and
        won't cause<br>
        this error. Changing a key is the only time it matters. Renewal
        does not<br>
        involve changing a key.<br>
        <br>
        If you really changed the key, then you would need to follow
        something<br>
        along the lines of <br>
        <a moz-do-not-send="true"
href="https://wiki.shibboleth.net/confluence/display/SHIB2/IdPKeyRollover">https://wiki.shibboleth.net/confluence/display/SHIB2/IdPKeyRollover</a><br>
        <br>
        -- Scott<br>
        <br>
        <br>
        --<br>
        To unsubscribe from this list send an email to
        <a class="moz-txt-link-abbreviated" href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
      </div>
      <br>
      <fieldset class="mimeAttachmentHeader"></fieldset>
      <br>
      <pre wrap="">--
To unsubscribe from this list send an email to <a class="moz-txt-link-abbreviated" href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a></pre>
    </blockquote>
    <br>
    <pre class="moz-signature" cols="72">-- 
-----------------------------------------------------------------------
Dr. Martin Haase
DAASI International GmbH                   phone:     +49 7071 407109-6
Europaplatz 3                              Fax  :     +49 7071 407109-9
D-72072 T&uuml;bingen                           email: <a class="moz-txt-link-abbreviated" href="mailto:Martin.Haase@DAASI.de">Martin.Haase@DAASI.de</a>
Germany                                    Web  :   <a class="moz-txt-link-freetext" href="http://www.daasi.de">http://www.daasi.de</a>

Directory Applications for Advanced Security and Information Management
-----------------------------------------------------------------------
</pre>
  </body>
</html>