<html><head></head><body>That's what I figured. The vendor is using ping federate and the Metadata they gave me had a cert in it. Had to munge it around to work with encrypt assertions after they enabled it on their end. Looking at the cert it appears to be the cert for their website. When we originally started configuring I had to disable encrypt assertions and it worked. Maybe I'll go back to that since it may be less hassle if they change the cert. And the transport is encrypted. <br><br><div class="gmail_quote">On August 3, 2016 5:19:49 PM EDT, IAM David Bantz <dabantz@alaska.edu> wrote:<blockquote class="gmail_quote" style="margin: 0pt 0pt 0pt 0.8ex; border-left: 1px solid rgb(204, 204, 204); padding-left: 1ex;">
<div dir="ltr"><div class="gmail_extra"><br /><div class="gmail_quote">On Wed, Aug 3, 2016 at 12:34 PM, Tom Scavo <span dir="ltr"><<a href="mailto:trscavo@gmail.com" target="_blank">trscavo@gmail.com</a>></span> wrote:<br /><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div id=":1nn" class="a3s aXjCH m156521de3fb6fc40">If you're an IdP running Shibboleth, then no, an expired cert in SP<br />
will not affect you....</div></blockquote></div><br />unless the SP starts using a different cert to sign requests or expects you to</div><div class="gmail_extra">use a newer cert to encrypt your response. It's not the expired date per se, but</div><div class="gmail_extra">the SP's reliance on a newer cert that can bite. That's happened to </div><div class="gmail_extra">my IdP when I let an SP's certificate expire instead of replacing it on time.</div></div>
<p style="margin-top: 2.5em; margin-bottom: 1em; border-bottom: 1px solid #000"></p><pre class="k9mail">-- <br />To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net</pre></blockquote></div></body></html>