<div dir="ltr">Thanks much for your help, Everyone. <br>I tried the whole situation locally and Shib IDP server indeed can handle the situation without any downtime. <br><br>- Configured Shibboleth SP with two certs ( first one with 1 year validity and second cert with 1 day validity ). <div>  - By adding type == chaining in CredentialResolver snippet in shibboleth2.xml</div><div>- Used SP's metadata ( which has two certs inside of it ) to create trust relationship here in IdP. <br>- 1 day valid cert expired today and there isn't issue in SSO. <br><br>Peter, I am sorry that I didn't mention about technical specification earlier. <br>I am using Gluu server. <br><br>- Gluu Server v2 ( shibboleth v2 included ) is auto reloading configuration in 5 mins interval. <div>- Gluu Server v3 ( shibboleth v3 included ) is auto reloading every min. </div></div></div><div class="gmail_extra"><br><div class="gmail_quote">On Thu, Sep 7, 2017 at 10:08 AM, Peter Schober <span dir="ltr"><<a href="mailto:peter.schober@univie.ac.at" target="_blank">peter.schober@univie.ac.at</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">* Zico <<a href="mailto:mailzico@gmail.com">mailzico@gmail.com</a>> [2017-09-07 15:18]:<br>
<span class="">> Seems like as vendor; I have nothing to do from IDP side to<br>
> participate in key rollover operation ( for any SP ).<br>
<br>
</span>I can't speak to any SAML implementation you may use (and you don't<br>
say) but at least when using the Shibboleth IDP there's nothing to do<br>
about SP key rollover -- which of course is the whole point of doing<br>
the steps of a key rollover properly.<br>
<span class=""><br>
> Say... I configured one SP five years back whose metadata containing<br>
> a 5 year valid cert and this cert is going to expire tomorrow.<br>
<br>
</span>Both the Shibboleth IDP and the SP support the<br>
"SAML V2.0 Metadata Interoperability Profile" out of the box:<br>
<a href="https://wiki.oasis-open.org/security/SAML2MetadataIOP" rel="noreferrer" target="_blank">https://wiki.oasis-open.org/<wbr>security/SAML2MetadataIOP</a><br>
As such certificate expiration (among other things) does not factor<br>
into the trustworthiness of a certificate at all.<br>
<br>
If you're using another software and/or a different trust model<br>
that may not be the case for you.<br>
<br>
You don't give any specifics, which is why you get <n> different<br>
answers.<br>
<span class=""><br>
> I know I can update/refresh their metadata "manually" tomorrow to<br>
> grab new cert but that might take 10 mins; what end user is trying<br>
> to achieve a zero downtime.<br>
<br>
</span>Are you saying you are using the Shibboleth IDP v3.3.x and<br>
reload-metadata.sh takes 10 minutes in your deployment?<br>
You'll have to provide more specifics if you want help with that.<br>
<br>
If you're not doing that then you're probably just Doing It Wrong™.<br>
Again, you don't mention technical details, so it's impossible to know<br>
or advise.<br>
<div class="HOEnZb"><div class="h5">-peter<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a></div></div></blockquote></div><br><br clear="all"><div><br></div>-- <br><div class="gmail_signature" data-smartmail="gmail_signature">Best,<br>Zico</div>
</div>