<div dir="ltr">Hi,Nate.<div><br></div><div>I apprecite for your quick reply.I will try the solution you suggested.</div><div class="gmail_extra"><br><div class="gmail_quote">2017-01-16 12:06 GMT+09:00 Klingenstein, Nate <span dir="ltr"><<a href="mailto:nklingenstein@calstate.edu" target="_blank">nklingenstein@calstate.edu</a>></span>:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div bgcolor="#FFFFFF" text="#000000">
<div class="m_-7881674146049800044moz-cite-prefix">武井,<br>
<br>
I think you understand the reasons why multiple signing credentials are bad: the exact situation that you're in right now. Scott was just trying to warn you to prevent you from ending up in that situation.<br>
<br>
Since you're already in that bad situation, let's help you out of it. You'll need to do 3 major things:<br>
<br>
1) Create special signing credentials bean in credentials.xml<br>
2) Define a special Security Configuration that points to that bean<br>
3) Refer to that Security Configuration from a RelyingPartyByName Override<br>
<br>
See particularly per-profile Credential in Signing and Encryption Configuration here:<br>
<br>
<a class="m_-7881674146049800044moz-txt-link-freetext" href="https://wiki.shibboleth.net/confluence/display/IDP30/SecurityConfiguration" target="_blank">https://wiki.shibboleth.net/<wbr>confluence/display/IDP30/<wbr>SecurityConfiguration</a><br>
<br>
Obviously, in the future, you'll want to consolidate your keypair and other credential usage to the extent possible.<br>
<br>
よろしくおねがいします,<br>
Nate.<div><div class="h5"><br>
<br>
On 01/16/2017 02:49 AM, 武井宜行 wrote:<br>
</div></div></div><div><div class="h5">
<blockquote type="cite">
<div dir="ltr">Hi
<div><br>
</div>
<div>I appreciate your reply.</div>
<div><br>
</div>
<div>In this case,I must migrate Shibboleth idp V2 to V3.</div>
<div>(Currently Shibboleth idp v2 is in use)</div>
<div><br>
</div>
<div>Because multiple signing credential is</div>
<div>now in use in Shibboleth idp v2,I must migrate this settings</div>
<div>to v3.</div>
<div><br>
</div>
<div>If multiple signing credential is not migrated to v3,</div>
<div>the impact is large because changeing the </div>
<div>metadata of some SPs is needed.</div>
<div><br>
</div>
<div>Could you tell me the way how I Use different</div>
<div>SigningCredential per Service Provider?</div>
<div><br>
</div>
</div>
<div class="gmail_extra"><br>
<div class="gmail_quote">2017-01-11 1:34 GMT+09:00 Cantor, Scott <span dir="ltr">
<<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span>:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<span>On 1/10/17, 11:20 AM, "users on behalf of 武井宜行" <<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a> on behalf of
<a href="mailto:ntakei@sios.com" target="_blank">ntakei@sios.com</a>> wrote:<br>
<br>
> I coud not find the solution in Shibboleth Wiki.<br>
<br>
</span>It's in the SecurityConfiguration topic. It is fairly complex to wire up, and this is something you should strongly reconsider doing in most cases, it's not a good idea. It usually reflects a lack of understanding by somebody somewhere. It's critically
important to push back on requirements dictated by people who don't know what they're doing or why.<br>
<span class="m_-7881674146049800044HOEnZb"><font color="#888888"><br>
-- Scott<br>
<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">
users-unsubscribe@shibboleth.n<wbr>et</a></font></span></blockquote>
</div>
<br>
<br clear="all">
<div><br>
</div><br><div class="m_-7881674146049800044gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div>
</div>
</div>
</div>
</div>
</blockquote>
<p><br>
</p>
</div></div></div>
<br>--<br><br></blockquote></div>
</div></div>