<div dir="ltr">After some fruitless searching to confirm this, I present this simple scenario:<div><br></div><div>- I have an IdP with many relying parties, most of them internal, some external.  We&#39;ve used the self-signed credential / cert generated at install</div>
<div>and never had the need to change this or supply metadata other than what is produced at /idp/profile/SAML/Metadata</div><div><br></div><div>- I have a new service provider (Equifax) that requires a cert issued by a trusted commercial CA</div>
<div><br></div><div>I&#39;ve obtained said cert, placed it and the private key in /credentials and modified the relying-party.xml configuration to utilize this cert for both signing and encryption</div><div>with the relying party.  </div>
<div><br></div><div>So, my questions:</div><div><br></div><div>- Do I also need to create a jks keystore as well?  Where is this referenced in the config?</div><div>- When giving my IdP metadata to the new relying party, I assume that, considering all other aspects of my IdP are the same as for my other relying-parties, I can simply replace the inline</div>
<div>x509 base64 text in my usual metadata info and give that to the relying-party</div><div><br></div><div>Any insight would be much appreciated.</div><div><br></div><div>--sean</div></div>