<div dir="ltr">Hi,<div><br></div><div>We have run into a situation that may require us to perform a key rollover in our IdP (v3.4.4). I've been looking for a "how to" or documentation specific to performing this task, but I've been unable to find anything helpful.<br><br>If folks here could point me to any kind of docs or reference materials I would be very grateful.<br><br>For background, the specific situation is:<br><br>An SP we work with (Ex Libris) upgraded their SP to Java 11, which by default does not like our signing cert. The error they sent me is: SAML failure 20: Certificate is not valid.  Cause: java.security.cert.CertPathValidatorException: Algorithm constraints check failed on signature algorithm: MD5withRSA.<br><br>They have requested that we upgrade our cert to meet their (suddenly, without notice) new security standards. I flat out told them no, so after some discussion their dev team did something (I'm guessing they adjusted the java security settings, but they are not telling me), and now we are working again, temporarily.<br><br>After some discussion with my director, we decided that it may be in our best interest, in the long run, to move forward with a controlled key rollover, so that this issue doesn't bite us in the future with other SPs.<br><br>Hopefully we can convince Ex Libris to keep this temporary work around in place until we have planned and can properly execute this key rollover.<br><div><br></div><div>Thanks,</div><div>-Brian</div>-- <br><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><font face="arial, sans-serif">Lead Identity Mgmt/Systems Integration<br>Information Technology<br>Sonoma State University</font><div><font face="arial, sans-serif"><br></font></div></div></div></div></div>