<div dir="ltr">Thank you all for the answers. Because I still do not have the answers, I will try to rephrase<div><br></div><div>IdP consumed this metadata:<br><font face="monospace, monospace">  <md:KeyDescriptor><br>    <ds:KeyInfo><br>    <ds:KeyName>Active</ds:KeyName<wbr>><br>...<br>  <md:KeyDescriptor><br>    <ds:KeyInfo><br>    <ds:KeyName>Standby</ds:KeyNam<wbr>e></font><br></div><div><br></div><div>SP has in shibboleth2.xml</div><div><div><font face="monospace, monospace">   <CredentialResolver type="File" keyName="Active" key=... <br></font></div><div><font face="monospace, monospace">   <CredentialResolver type="File" keyName="Standby" key=...<br></font></div></div><div><br></div><div>Let a user try to auth. via the IdP to the SP:</div><div>1. Will it work?</div><div>2. What if Active/Standby are vice versa at one of them?</div><div><br></div><div><br></div><div>Another case study, IdP consumed this metadata:</div><div><div><font face="monospace, monospace">  <md:KeyDescriptor><br>    <ds:KeyInfo><br>    <ds:KeyName>Active</ds:KeyName<wbr>><br></font></div><div><font face="monospace, monospace"><br></font></div><div>SP has in shibboleth2.xml</div><div><div><font face="monospace, monospace">   <CredentialResolver type="File" keyName="Active" key=... <br></font></div><div><font face="monospace, monospace">   <CredentialResolver type="File" keyName="Standby" key=...<br></font></div></div><div><br></div><div><br></div><div>3. Will it work?</div><div>4. What if Active/Standby are vice versa at the SP?<br></div><div><br></div><div>Best,<br></div><div>Jozef</div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div class="gmail_extra"><br><div class="gmail_quote">On 3 March 2017 at 15:10, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span>On 3/3/17, 9:04 AM, "users on behalf of Tom Scavo" <<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a> on behalf of <a href="mailto:trscavo@gmail.com" target="_blank">trscavo@gmail.com</a>> wrote:<br>
<br>
> Right, which is why multiple encryption certificates in metadata is not recommended.<br>
<br>
</span>As long as the consumer can wield all of them, it's generally fine, and it can be quite complex to pull off "multiple signing keys but just one encryption key" with a lot of federations. Which I imagine relates to the OP's concern. It's very hard to get things to work if there are federations imposing constraints.<br>
<span class="m_-4062137683684274331m_6511526491831297455HOEnZb"><font color="#888888"><br>
-- Scott<br>
</font></span><div class="m_-4062137683684274331m_6511526491831297455HOEnZb"><div class="m_-4062137683684274331m_6511526491831297455h5"><br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.n<wbr>et</a><br>
</div></div></blockquote></div><br></div></div>