<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=Windows-1252">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; color: rgb(0, 0, 0); font-size: 14px; font-family: Calibri, sans-serif; ">
<div>Carl,</div>
<div><br>
</div>
<div>Are you referring to the public/private key used by Shibboleth SP to sign authentication requests? Or are you referring to an SSL certificate used to provide confidentiality to your web server? If the later, then Shibboleth does not care. The transport
 layer security is before Shib gets involved. You can secure it as you would any SSL protected site.</div>
<div><br>
</div>
<div>If the former, you'll need to create your private key, then a certificate signing request, and then have a commercial CA sign it. Then you will have the private key and signed public key to use in your Shibboleth configuration. Note that Shibboleth does
 not care about SAML signing keys being &quot;signed&quot; by a commercial CA. Also note it adds no additional trust or security to do so. Trust is established by you furnishing your public key to the IdP by an out of band process and them trusting it was you that furnished
 it. Having a commercial CA sign that key adds no value. It does however cause you to keep up with its expiration date year in and year out.</div>
<div><br>
</div>
<div>Paul</div>
<div><br>
</div>
<span id="OLK_SRC_BODY_SECTION">
<div style="font-family:Calibri; font-size:11pt; text-align:left; color:black; BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 0in; PADDING-RIGHT: 0in; BORDER-TOP: #b5c4df 1pt solid; BORDER-RIGHT: medium none; PADDING-TOP: 3pt">
<span style="font-weight:bold">From: </span>Carl Buxbaum &lt;<a href="mailto:cbuxbaum@tradestonesoftware.com">cbuxbaum@tradestonesoftware.com</a>&gt;<br>
<span style="font-weight:bold">Reply-To: </span>Shibboleth Users &lt;<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>&gt;<br>
<span style="font-weight:bold">Date: </span>Monday, February 11, 2013 3:31 PM<br>
<span style="font-weight:bold">To: </span>Shibboleth Users &lt;<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>&gt;<br>
<span style="font-weight:bold">Subject: </span>question about Service Provider Cert<br>
</div>
<div><br>
</div>
<div xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<meta name="Generator" content="Microsoft Word 12 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
span.EmailStyle17
        {mso-style-type:personal-compose;
        font-family:"Calibri","sans-serif";
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
<div lang="EN-US" link="blue" vlink="purple">
<div class="WordSection1">
<p class="MsoNormal">Hi,<o:p></o:p></p>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
<p class="MsoNormal">I am trying to get a handle on the certificate installation for a Service Provider implementation.&nbsp; I successfully developed and tested a SP &nbsp;IDP initiated SSO implementation using a self signed certificate against the Shibboleth IDP, but
 the customer requires a CA issued cert.&nbsp; According to the documentation of the CA, they talk about generating a cert request, and then importing the entire certificate chain into my SP keystore.&nbsp; Since I already have the private key in my keystore, do I really
 need to import anything else after running keytool –genkey? Do I need to import the resulting cert into the IDP?&nbsp; And the rest of the cert chain? Or do I just take the resulting cert and place it in the metadata for the Identity Provider? &nbsp;The Identity Provider
 they are using is PingFederate.<o:p></o:p></p>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
<p class="MsoNormal">Thanks for the help.<o:p></o:p></p>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
<p class="MsoNormal"><b><span style="font-size:10.0pt;color:navy">Carl&nbsp; Buxbaum<o:p></o:p></span></b></p>
<p class="MsoNormal"><span style="font-size:10.0pt;color:navy">Software Architect<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;color:navy">TradeStone Software<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;color:navy">17 Rogers St. Suite 2; Gloucester, MA 01930<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;color:#002060">P: 978-515-5128
</span><span style="font-size:10.0pt;color:navy">F : 978-281-0673<o:p></o:p></span></p>
<p class="MsoNormal"><a href="http://www.tradestonesoftware.com"><span style="font-size:10.0pt;color:blue">www.tradestonesoftware.com</span></a><span style="font-size:12.0pt"><o:p></o:p></span></p>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
</div>
<br clear="both">
DISCLAIMER: <br>
E-mails and attachments from TradeStone Software, Inc. are confidential.<br>
If you are not the intended recipient, please notify the sender immediately by<br>
replying to the e-mail, and then delete it without making copies or using it<br>
in any way. No representation is made that this email or any attachments are<br>
free of viruses. Virus scanning is recommended and is the responsibility of<br>
the recipient.<br>
</div>
</div>
</span>
</body>
</html>