<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class="">
Izz,
<div class=""><br class="">
</div>
<div class="">
<div>
<blockquote type="cite" class="">
<div class="">
<div class="WordSection1" style="page: WordSection1; font-family: Helvetica; font-size: 12px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px;">
<div style="margin: 0in 0in 0.0001pt 0.5in; line-height: 12pt; font-size: 11pt; font-family: Calibri, sans-serif; text-indent: -0.25in;" class="">
<span style="font-family: 'Times New Roman', serif; color: windowtext;" class=""><span class="">1.<span style="font-style: normal; font-variant-caps: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-family: 'Times New Roman';" class="">     <span class="Apple-converted-space"> </span></span></span></span><span style="font-family: 'Times New Roman', serif; color: windowtext;" class="">Just
 removing the old certificate from the metadata with InCommon</span></div>
</div>
</div>
</blockquote>
<div><br class="">
</div>
<div>I can't think of a way that would be unsafe.</div>
<br class="">
<blockquote type="cite" class="">
<div class="WordSection1" style="page: WordSection1; font-family: Helvetica; font-size: 12px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px;">
<div style="margin: 0in 0in 0.0001pt 0.5in; line-height: 12pt; font-size: 11pt; font-family: Calibri, sans-serif; text-indent: -0.25in;" class="">
<span style="font-family: 'Times New Roman', serif; color: windowtext;" class=""><o:p class=""></o:p></span></div>
<div style="margin: 0in 0in 0.0001pt 0.5in; line-height: 12pt; font-size: 11pt; font-family: Calibri, sans-serif; text-indent: -0.25in;" class="">
<span style="font-family: 'Times New Roman', serif; color: windowtext;" class=""><span class="">2.<span style="font-style: normal; font-variant-caps: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-family: 'Times New Roman';" class="">     <span class="Apple-converted-space"> </span></span></span></span><span style="font-family: 'Times New Roman', serif; color: windowtext;" class="">Leaving
 the certificate which is about to expire, since it isn’t used<o:p class=""></o:p></span></div>
<div style="margin: 0in 0in 0.0001pt 1in; line-height: 12pt; font-size: 11pt; font-family: Calibri, sans-serif; text-indent: -0.25in;" class="">
<span style="font-family: 'Times New Roman', serif; color: windowtext;" class=""><span class="">a.<span style="font-style: normal; font-variant-caps: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-family: 'Times New Roman';" class="">      <span class="Apple-converted-space"> </span></span></span></span><span style="font-family: 'Times New Roman', serif; color: windowtext;" class="">For
 informational purposes.  Are there cases where configs would reject metadata if an expired certificate is in it, although no longer utilized?</span></div>
</div>
</blockquote>
<div><br class="">
</div>
<div>That's a better question.  I would rephrase:</div>
<div><br class="">
</div>
<div>If the certificate is not bad right now, are all the providers in InCommon using implementations that skim over a bad certificate, even if they aren't using it?</div>
<div><br class="">
</div>
<div>I would suspect yes and InCommon's policies should reflect that, but "stranger things have happened".</div>
<div><br class="">
</div>
<div>Hope this helps,</div>
<div>Nate.</div>
</div>
</div>
</body>
</html>