<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
</head>
<body>
<div dir="auto" style="direction: ltr; margin: 0; padding: 0; font-family: sans-serif; font-size: 11pt; color: black; ">
Have SPs pointing to expiring signing cert point to new cert when they receive updated IDP metadata.</div>
<hr style="display:inline-block;width:98%" tabindex="-1">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" style="font-size:11pt" color="#000000"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Cantor, Scott <cantor.2@osu.edu><br>
<b>Sent:</b> Tuesday, February 4, 2020 5:38:35 PM<br>
<b>To:</b> Shib Users <users@shibboleth.net><br>
<b>Subject:</b> RE: IDP 3.4.3 Expiring Signing Certtificate Rollover</font>
<div> </div>
</div>
<div class="BodyFragment"><font size="2"><span style="font-size:11pt;">
<div class="PlainText">WARNING: This email originated from outside of UTMB's email system. Do not click links or open attachments unless you recognize the sender and know the content is safe.<br>
<br>
<br>
> I have verified that old and new signing cert works but only one at a time<br>
> depending on which bean is not commented out or which bean is first within<br>
> util:list in credentials.xml<br>
<br>
What exactly are you expecting to happen? Any given security and signing configuration is going to use exactly one key, and other than exceptional cases involving different key types, there's no concept of picking a key based on anything other than a local
decision over which key to use.<br>
<br>
> Haven't found other documentation.<br>
<br>
Controlling credentials is documented in [1]<br>
<br>
-- Scott<br>
<br>
[1] <a href="https://nam03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwiki.shibboleth.net%2Fconfluence%2Fdisplay%2FIDP30%2FSecurityConfiguration&data=02%7C01%7Crcthomas%40utmb.edu%7Cc54b14a646ce4c6edb3b08d7a9cb6851%7C7bef256d85db4526a72d31aea2546852%7C0%7C0%7C637164563421032010&sdata=uiDU663bU987Apw%2BR3844t6%2BalVutwtrYy4%2FShk7aJM%3D&reserved=0">
https://nam03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwiki.shibboleth.net%2Fconfluence%2Fdisplay%2FIDP30%2FSecurityConfiguration&data=02%7C01%7Crcthomas%40utmb.edu%7Cc54b14a646ce4c6edb3b08d7a9cb6851%7C7bef256d85db4526a72d31aea2546852%7C0%7C0%7C637164563421032010&sdata=uiDU663bU987Apw%2BR3844t6%2BalVutwtrYy4%2FShk7aJM%3D&reserved=0</a><br>
--<br>
For Consortium Member technical support, see <a href="https://nam03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwiki.shibboleth.net%2Fconfluence%2Fx%2FcoFAAg&data=02%7C01%7Crcthomas%40utmb.edu%7Cc54b14a646ce4c6edb3b08d7a9cb6851%7C7bef256d85db4526a72d31aea2546852%7C0%7C0%7C637164563421032010&sdata=JRBAug%2FkBw3XnYYx26YNr9XK5CPFsdO5C3AYeL3lPPU%3D&reserved=0">
https://nam03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwiki.shibboleth.net%2Fconfluence%2Fx%2FcoFAAg&data=02%7C01%7Crcthomas%40utmb.edu%7Cc54b14a646ce4c6edb3b08d7a9cb6851%7C7bef256d85db4526a72d31aea2546852%7C0%7C0%7C637164563421032010&sdata=JRBAug%2FkBw3XnYYx26YNr9XK5CPFsdO5C3AYeL3lPPU%3D&reserved=0</a><br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div>
</span></font></div>
</body>
</html>