<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class="">
Scott,
<div class=""><br class="">
</div>
<div class="">Thank you for looking into it. Individual who first set it up, doesn’t work here anymore, we have some documentation that we can reference. </div>
<div class="">Yes there was a password used to encrypt. We are using the same pwd to generate the new pair. </div>
<div class="">Unfortunately, we had to do a from-scratch implementation - and are now wanting to re-use the old keypair (if it’s an option).</div>
<div class="">We are doing a Dockerized IdP installation for our campuses, so we decided to do a clean install.</div>
<div class=""><br class="">
</div>
<div class="">Can you please point me to any documentation of config changes required for from-scratch installation to support a password-protected key? I will communicate this to the Sys Admin who is setting it up. I am reading some info here, but not on how
 to change the IDP setup.</div>
<div class=""><br class="">
</div>
<div class=""><a href="https://wiki.shibboleth.net/confluence/display/IDP30/SecurityAndNetworking#SecurityAndNetworking-EncryptionKeyandCertificate" class="">https://wiki.shibboleth.net/confluence/display/IDP30/SecurityAndNetworking#SecurityAndNetworking-EncryptionKeyandCertificate</a></div>
<div class=""><br class="">
</div>
<div class="">We used the same keypair for signing and encryption.. and plan to do the same for V3(if possible). </div>
<div class="">We are not using a legacy relying-party.xml or other files, the only thing legacy is some definitions in attribute-resolver.xml for EPTID etc which have been said to be compatible for V3. </div>
<div class=""> </div>
<div class=""><br class="">
</div>
<div class="">Thanks again,</div>
<div class="">Shweta </div>
<div class=""><br class="">
</div>
<div class=""><br class="">
<div>
<blockquote type="cite" class="">
<div class="">On Aug 12, 2016, at 2:04 PM, Cantor, Scott <<a href="mailto:cantor.2@osu.edu" class="">cantor.2@osu.edu</a>> wrote:</div>
<br class="Apple-interchange-newline">
<div class="">I found the error message in the Java library, but it's not particularly<br class="">
informative other than the obvious.<br class="">
<br class="">
I assume you know whether the key was encrypted with a password, and I<br class="">
also don't know if you're doing a proper upgrade or if you ignored our<br class="">
instructions and tried to do it from scratch and are now trying to copy<br class="">
back the old keypair. The default from-scratch install does not<br class="">
configure things to support a password-protected key. A legacy<br class="">
relying-party file would have the password in it, probably, but that<br class="">
wouldn't work with a non-upgraded install.<br class="">
<br class="">
Lot of variables here, none of them provided in the email to the list.<br class="">
<br class="">
-- Scott<br class="">
-- <br class="">
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" class="">
users-unsubscribe@shibboleth.net</a><br class="">
</div>
</blockquote>
</div>
<br class="">
</div>
</body>
</html>