<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; color: rgb(0, 0, 0); font-size: 14px; font-family: Calibri, sans-serif; ">
<div>Hello,</div>
<div><br>
</div>
<div>We have shibboleth idp with self signed certificate and federated with many SPs, but recently a vendor requires us to use commercial certificate for the federation.</div>
<div><br>
</div>
<div>I saw on the shib wiki that sp can have credential resolver chaining to use multiple cert, I can't find similar topic related to the idp.</div>
<div><br>
</div>
<div>Chance of the vendor allowing us to use self signed cert is very low, we would like not to set up another Idp just for this vendor. So what is my options?</div>
<div><br>
</div>
<div>Regards,</div>
<div>Yi</div>
</body>
</html>