<div dir="ltr"><div><div>Recently, we decided to make a switch from Blackboard 
Collaborate to the Webex platform and have happy SSO-enabled our WebEx 
installation. However, to offer WebEx through our LMS (Canvas, which is 
also SSO-enabled), we plan to make sure of a 3rd party called Cirqlive. 
Long story short, users have two entry ways to use Webex... one by going
 directly to WebEx through the traditional interface and another by way 
of Canvas and the Cirqlive (LTI tool). So in order to make all this 
happen, Cirqlive wants to by design play man-in-the-middle and needs 
access to our IdP's private key... nothing something I'm at all 
comfortable giving out generally speaking. However, since shibb supports
 handing of multiple keys, the though process is to generate a unique 
private key only used for the WebEx relying party and then feel more 
comfortable in allowing Cirqlive to have access to it (protecting all 
the other SPs that aren't involved in this weird setup). <br><br></div>So
 my question is, what is the best way to generate a new IdP cert not to 
replace the one our IdP is using, but an additional one that will be 
just for WebEx? Can this be done with <code><strong>./install.sh renew-cert </strong></code>and
 rather than replace, just keep the old and new and plumb the new into 
the WebEx relying party? Am I thinking about this correctly? Anybody 
else using WebEx with Cirqlive?<br><br></div><div>This architecture I am referring to can be seen as Architecture #1 in Cirqlive's own documentation:<br><div><a href="https://documentation.cirqlive.com/manuals/SSO/Overview_Multi-Source_SAML_Authentication_with_WebEx_%28MEETS%29.pdf" target="_blank">https://documentation.<span class="">cirqlive</span>.com/manuals/SSO/Overview_Multi-Source_SAML_Authentication_with_WebEx_(MEETS).pdf</a><br></div><div><div><a href="https://documentation.cirqlive.com/manuals/SSO/Multi-Source_SAML_Authentication_with_WebEx_%28MEETS%29.pdf" target="_blank">https://documentation.<span class="">cirqlive</span>.com/manuals/SSO/Multi-Source_SAML_Authentication_with_WebEx_(MEETS).pdf</a><br></div><div><br></div></div><br></div>-Rob<br clear="all"><br>-- <br><div class="gmail_signature"><div dir="ltr"><div>Robert W. Gorrell<br>Systems Architect, Identity and Access Management </div>
<div>University of NC at Greensboro<br><span style="white-space:nowrap">336-334-5954</span><br>PGP Key ID B36DB0CA<br></div></div></div>
</div>