<div dir="ltr">Well, we brought up a new IdP, with new certs and a new entityID. I've already been working with all of our SPs to get them the new metadata and certs and so forth, if that's what you mean about a long process. (And yes, it's been a long haul.)<div><br></div><div>That's the situation. We only have a couple of SPs that use our InCommon metadata, but I need to change it to point to the new one. So, the question remains: which one should I use? (Not encryption, I know that now.) What would someone do if their v3 IdP were a new addition to InCommon?</div><div><br></div><div>Thanks,</div><div>Karla</div></div><div class="gmail_extra"><br><div class="gmail_quote">On Mon, Mar 14, 2016 at 2:47 PM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="">> I was about to change our InCommon IdP information to list our v3 IdP, but<br>
> I'm not sure which certificate I should be uploading. The signing one? All<br>
> three?<br>
<br>
</span>You shouldn't be changing anything. Your IdP should be using the same signing key as before. If you were using it for SOAP, then you should also be using that key for your container's SOAP port. The only reason you should be changing a key is if it's compromised, or if you want to roll out a new one, in which case you have a very long process ahead and you can't do it by just changing the key all at once.<br>
<br>
InCommon does not have support for encryption-only keys so there's nothing you can do with the separate key at the moment in the federation's mtadata interface.<br>
<br>
If there's something in the SecurityAndNetworking topic you don't understand, you should absolutely stop until you do, and ask about it.<br>
<span class="HOEnZb"><font color="#888888"><br>
-- Scott<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</font></span></blockquote></div><br><br clear="all"><div><br></div>-- <br><div class="gmail_signature"><div style="margin-left:40px">Karla Borecky<br>Systems Administrator<br>ITS<br>Smith College<br>Northampton, MA 01063<br></div></div>
</div>