<div dir="ltr"><div>Well ! Following section is from the UK Federation site (<a href="http://www.ukfederation.org.uk/content/Documents/GetCertificatesSh2IdP">http://www.ukfederation.org.uk/content/Documents/GetCertificatesSh2IdP</a>) :</div><div><br></div><div>"To set up a Shibboleth 2.x IdP entity within the UK federation you will normally require two X.509 digital certificates:<br>a trust-fabric certificate for machine-to-machine use, and<br>a browser-facing certificate that users will see</div><div><br>These two certificates are used for different purposes and have different properties:<br>A self-signed certificate with a lifetime of 10 or 20 years is recommended for the trust fabric certificate<br>An SSL certificate from a commercial Certification Authority (CA) is required for the browser-facing certificate"</div><div><br></div><div><br></div><div>To come to the point raised in my initial post. We are planning for a certificate rollover in our sp since the existing certificate is expiring next month. Previously we had a single certificate but now we have an intermediate certificate in addition to the certificate. My question is what should be the correct way to incorporate the certificate in the sp metadata xml. The metadata is an xml file created manually ("/sp-metadata.xml"). It is NOT the auto generated one from Shibboleth.sso (i.e. "/Shibboleth.sso/Metadata"). </div><div><br></div><div><br></div></div><div class="gmail_extra"><br><div class="gmail_quote">On Mon, Jun 27, 2016 at 8:38 PM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="">> My question was for sp certificate rollover as mentioned by the following<br>
> Shibboleth federations:<br>
<br>
</span>And that has nothing to do with changing a browser-facing certificate.<br>
<div class="HOEnZb"><div class="h5"><br>
-- Scott<br>
<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br></div>