<div dir="ltr"><div>My question was for sp certificate rollover as mentioned by the following Shibboleth federations:<br></div><div><br></div><div>1. <a href="https://www.switch.ch/aai/guides/sp/certificate-rollover/">https://www.switch.ch/aai/guides/sp/certificate-rollover/</a></div><div>2. <a href="http://www.ukfederation.org.uk/content/Documents/GetCertificatesSh2SP#rollover">http://www.ukfederation.org.uk/content/Documents/GetCertificatesSh2SP#rollover</a></div></div><div class="gmail_extra"><br><div class="gmail_quote">On Mon, Jun 27, 2016 at 8:21 PM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="">> I am trying to upgrade the browser-facing certificate on the Service Provider<br>
> (sp).<br>
<br>
</span>That has no connection to the SP.<br>
<span class=""><br>
> Then I have updated shibboleth2.xml (after notifying all the stakeholders<br>
> about the change) to point to the new certificate:<br>
<br>
</span>No, stop, undo, never. Is that clear enough? Do NOT do this.<br>
<span class=""><br>
> However I have couple of questions how to update the sp-metadata.xml<br>
> with the new certificate:<br>
<br>
</span>You don't.<br>
<span class="HOEnZb"><font color="#888888"><br>
-- Scott<br>
<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</font></span></blockquote></div><br></div>