<div dir="ltr">Thanks much Peter and Alan for your guidance. <br>Seems like as vendor; I have nothing to do from IDP side to participate in key rollover operation ( for any SP ). <br><br>But.. a quick question.... <br><br>Say... I configured one SP five years back whose metadata containing a 5 year valid cert and this cert is going to expire tomorrow. <br>Now, if they push 2nd cert in their SP metadata ( by using SP Key rollover configuration ).... don't I need to do anything at all from IDP side? Because... as IDP... that new / 2nd cert is unknown to me. <br>I know I can update/refresh their metadata "manually" tomorrow to grab new cert but that might take 10 mins; what end user is trying to achieve a zero downtime. <br><br><br></div><div class="gmail_extra"><br><div class="gmail_quote">On Thu, Sep 7, 2017 at 7:34 AM, Alan Buxey <span dir="ltr"><<a href="mailto:alan.buxey@myunidays.com" target="_blank">alan.buxey@myunidays.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">clearly documented (along with the Shibboleth method).<br>
<br>
<a href="https://spaces.internet2.edu/display/InCFederation/SP+Cert+Migration" rel="noreferrer" target="_blank">https://spaces.internet2.edu/<wbr>display/InCFederation/SP+Cert+<wbr>Migration</a><br>
<br>
(note that InCommon method slightly differs to the Shibboleth method<br>
since it avoids having 2 certs present..... not an issue for<br>
shibboleth...and issue for<br>
other SAML implementations so InCommon take that into consideration)<br>
<br>
alan<br>
<div><div class="h5"><br>
<br>
On 7 September 2017 at 12:52, Zico <<a href="mailto:mailzico@gmail.com">mailzico@gmail.com</a>> wrote:<br>
><br>
><br>
> On Thu, Sep 7, 2017 at 6:45 AM, Peter Schober <<a href="mailto:peter.schober@univie.ac.at">peter.schober@univie.ac.at</a>><br>
> wrote:<br>
>><br>
>> * Zico <<a href="mailto:mailzico@gmail.com">mailzico@gmail.com</a>> [2017-09-07 13:26]:<br>
>> > If any SP has two SAML certificates in it's metadata, can Shib IdP<br>
>> > support<br>
>> > that?<br>
>><br>
>> Yes.<br>
><br>
><br>
> Very nice!!! Any doc or something like that?<br>
><br>
><br>
>><br>
>><br>
>> > What I am asking is more like how Incommon handles cert<br>
>> > migration.... keep existing soon-to-be-expired cert in<br>
>> > metadata... add new metadata.... so there are two metadata<br>
>> > available. When old cert is expired; there is no outage as new cert<br>
>> > is already being used there.<br>
>><br>
>> Yes. Check the extensive InCommon documentation on key rollover if<br>
>> you're an InCommon participant.<br>
><br>
><br>
> I am not InCommon participant personally but I'll check how to do 'key<br>
> rollover in Shibboleth IDP' if there is any.<br>
><br>
><br>
>><br>
>><br>
>> -peter<br>
>> --<br>
>> To unsubscribe from this list send an email to<br>
>> <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br>
><br>
><br>
><br>
><br>
> --<br>
> Best,<br>
> Zico<br>
><br>
> --<br>
> To unsubscribe from this list send an email to<br>
> <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br>
<br>
<br>
<br>
--<br>
</div></div>Alan Buxey<br>
Senior Verification Engineer<br>
<br>
<br>
<br>
UNiDAYS<br>
The world’s leading Student Affinity Network<br>
<br>
Visit <a href="http://myunidays.com" rel="noreferrer" target="_blank">myunidays.com</a><br>
Find us on Facebook<br>
Learn more on our corporate site<br>
<br>
UNiDAYS can verify 70% of the world's 200 million students across 32 countries<br>
<br>
<br>
<br>
This email and any files transmitted with or attached to it contain<br>
information which is private, confidential and privileged. This<br>
information is intended solely for the use of the intended recipient<br>
to whom it is addressed.  If you are not the intended recipient, you<br>
are hereby notified that any disclosure, copying,  distribution, or<br>
the taking of any action in reliance on the contents of this<br>
electronic transmission is strictly prohibited, and that the<br>
information should be returned to MyUnidays Limited immediately.  If<br>
you have received this email in error please notify the sender<br>
immediately and permanently delete the original and any copies of this<br>
email and any attachments thereto. Thank you.<br>
<div class="HOEnZb"><div class="h5">--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a></div></div></blockquote></div><br><br clear="all"><div><br></div>-- <br><div class="gmail_signature" data-smartmail="gmail_signature">Best,<br>Zico</div>
</div>