<div dir="ltr">Thank you for the great information. It helped me a lot to understand communication. You are saying<div> <span style="font-size:12.8000001907349px"> </span><span style="font-size:12.8000001907349px">to sign the assertion it needs a private key (this will be in the credentials folder in a standard IdP installation). Actually we have that folder(credentials) which is empty. If you see my query which i have mentioned that <b>SP </b>is our own.</span></div><div><span style="font-size:12.8000001907349px"><br></span></div><div><span style="font-size:12.8000001907349px">Recently Openssl announced that some of issues <a href="https://www.openssl.org/news/vulnerabilities.html">openssl vulnerabilities</a>, to avoid those issues we have to update</span></div><div><span style="font-size:12.8000001907349px">our certificate which is placed in idp-metadata.xml. I think we do not need to upgrade shibboleth-idp.jar for this.</span></div><div><span style="font-size:12.8000001907349px">So we have to create certificate again with the latest openssl version to avoid openssl vulnerabilities.</span></div><div><span style="font-size:12.8000001907349px"><br></span></div><div><span style="font-size:12.8000001907349px">I can able to see only the &lt;ds:X:509 Certificate&gt; certificate in the idp-metadata.xml except that i don&#39;t see any other keys(pvt key) in credentials folder. I don&#39;t see any </span><span style="font-size:12.8000001907349px">IdP Certificate/Key pair in the conf folder. We have only .xml configuration files in the <b>conf</b> folder. we are not using <b>login.config </b>file from the <b>conf folder.</b></span></div><div><span style="font-size:12.8000001907349px"><b><br></b></span></div><div><span style="font-size:12.8000001907349px">I am able to see only one certificate which in idp-metadata.xml not more.</span></div><div><span style="font-size:12.8000001907349px"><br></span></div><div><span style="font-size:12.8000001907349px">I hope you can understand my scenario. Please help me.</span></div><div><span style="font-size:12.8000001907349px"><br></span></div><div><span style="font-size:12.8000001907349px">Thanks a lot for your valuable time. </span></div></div><div class="gmail_extra"><br><div class="gmail_quote">On Fri, Mar 27, 2015 at 5:02 PM, Rod Widdowson <span dir="ltr">&lt;<a href="mailto:rdw@steadingsoftware.com" target="_blank">rdw@steadingsoftware.com</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="">&gt; &gt; With one ridiculous exception (which is not relevant and we&#39;ll ignore)<br>
the IdP<br>
&gt; metadata is *not* configuration for the IdP.<br>
&gt;<br>
&gt; Okay, I&#39;ll bite, can you elaborate on this?<br>
<br>
</span>Artifact configuration.  In V2 the IdP reaches into its own metadata to find<br>
out what it should be doing.  We killed that in V3, Scott got to lead the<br>
ceremony.<br>
<div class="HOEnZb"><div class="h5"><br>
<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br></div>