<div dir="ltr"><div class="gmail_extra"><br><div class="gmail_quote">On Wed, Aug 3, 2016 at 12:34 PM, Tom Scavo <span dir="ltr"><<a href="mailto:trscavo@gmail.com" target="_blank">trscavo@gmail.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div id=":1nn" class="a3s aXjCH m156521de3fb6fc40">If you're an IdP running Shibboleth, then no, an expired cert in SP<br>
will not affect you....</div></blockquote></div><br>unless the SP starts using a different cert to sign requests or expects you to</div><div class="gmail_extra">use a newer cert to encrypt your response. It's not the expired date per se, but</div><div class="gmail_extra">the SP's reliance on a newer cert that can bite. That's happened to </div><div class="gmail_extra">my IdP when I let an SP's certificate expire instead of replacing it on time.</div></div>