<HTML><HEAD>
<META content="text/html; charset=utf-8" http-equiv=Content-Type>
<META name=GENERATOR content="MSHTML 9.00.8112.16447"></HEAD>
<BODY style="MARGIN: 4px 4px 1px; FONT: 10pt Segoe UI" bgColor=#ffffff text=#000000>
<DIV>Martin</DIV>
<DIV> </DIV>
<DIV>This document has been very helpful... I truly appreciate your help.</DIV>
<DIV> </DIV>
<DIV>Have a great day</DIV>
<DIV>Wavyne Belance<BR><BR>>>> Martin Haase <Martin.Haase@DAASI.de> 9/12/2012 10:42 AM >>><BR>Hi Wavyne,<BR><BR>if it is of any help - I find the following two pages very useful:<BR></DIV>
<P><A class="external free" title=https://www.switch.ch/aai/docs/shibboleth/SWITCH/sp-certificate-rollover.html href="https://www.switch.ch/aai/docs/shibboleth/SWITCH/sp-certificate-rollover.html" rel=nofollow>https://www.switch.ch/aai/docs/shibboleth/SWITCH/sp-certificate-rollover.html</A> </P>
<P><A class="external free" title=https://www.switch.ch/aai/docs/shibboleth/SWITCH/idp-certificate-rollover.html href="https://www.switch.ch/aai/docs/shibboleth/SWITCH/idp-certificate-rollover.html" rel=nofollow>https://www.switch.ch/aai/docs/shibboleth/SWITCH/idp-certificate-rollover.html</A><BR></P>
<P>Cheers,<BR>Martin<BR></P><BR>
<DIV class=moz-cite-prefix>Am 12.09.2012 16:49, schrieb Wavyne Belance:<BR></DIV>
<BLOCKQUOTE cite=mid:50505A990200007E000602E4@gwials1.is-svr.luc.edu type="cite">
<META name=GENERATOR content="MSHTML 9.00.8112.16447">
<DIV>Hello Scott </DIV>
<DIV> </DIV>
<DIV>Thanks for your explanation. I have a few follow-up questions:</DIV>
<DIV> </DIV>
<DIV>When the certificate in the metadata file expires, then I should not make changes within the relying-party file to reflect the renewed cert?</DIV>
<DIV> </DIV>
<DIV>As you stated when you renewed the certificate, you don't have to change the key in the relying-party file, but the SP gets a different certificate than the one in the metadata if the key isn't also renewed, correct?</DIV>
<DIV> </DIV>
<DIV>When would I need to update the key and the certificate in the relying-party file?</DIV>
<DIV> </DIV>
<DIV>And what certificate should be in the metadata file? The CA signed certificate or the server issued certificate being referenced in the relying-party file?</DIV>
<DIV> </DIV>
<DIV>Thanks again</DIV>
<DIV>Wavyne Belance<BR><BR>>>> "Cantor, Scott" <A class=moz-txt-link-rfc2396E href="mailto:cantor.2@osu.edu"><cantor.2@osu.edu></A> 9/11/2012 8:52 AM >>><BR>On 9/11/12 7:29 AM, "Wavyne Belance" <A class=moz-txt-link-rfc2396E href="mailto:wbelance@luc.edu"><wbelance@luc.edu></A> wrote:<BR>><BR>>The certificate is updated in my metadata and its location and the key<BR>>are in the relying-party.xml file. I also see the saml2 assertion being<BR>>sent with the correct certificate when I turn debugging on. Where did I<BR>>go wrong?<BR><BR>You're using the wrong key, the metadata's wrong, or the SP doesn't have<BR>the metadata you think it does.<BR><BR>>Are there step by step guides to renewing the Shibboleth certificate?<BR><BR>Several. But renewing a certificate is mostly irrelevant and won't cause<BR>this error. Changing a key is the only time it matters. Renewal does not<BR>involve changing a key.<BR><BR>If you really changed the key, then you would need to follow something<BR>along the lines of <BR><A href="https://wiki.shibboleth.net/confluence/display/SHIB2/IdPKeyRollover" moz-do-not-send="true">https://wiki.shibboleth.net/confluence/display/SHIB2/IdPKeyRollover</A><BR><BR>-- Scott<BR><BR><BR>--<BR>To unsubscribe from this list send an email to <A class=moz-txt-link-abbreviated href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</A><BR></DIV><BR>
<FIELDSET class=mimeAttachmentHeader></FIELDSET> <BR><PRE wrap="">--
To unsubscribe from this list send an email to <A class=moz-txt-link-abbreviated href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</A></PRE></BLOCKQUOTE><BR><PRE class=moz-signature cols="72">--
-----------------------------------------------------------------------
Dr. Martin Haase
DAASI International GmbH phone: +49 7071 407109-6
Europaplatz 3 Fax : +49 7071 407109-9
D-72072 Tübingen email: <A class=moz-txt-link-abbreviated href="mailto:Martin.Haase@DAASI.de">Martin.Haase@DAASI.de</A>
Germany Web : <A class=moz-txt-link-freetext href="http://www.daasi.de">http://www.daasi.de</A>
Directory Applications for Advanced Security and Information Management
-----------------------------------------------------------------------
</PRE></BODY></HTML>