<div dir="ltr">Hi,<div><br></div><div>I have finally reached the bottom of the rabbit hole. I have inherited an IdP that is using a signing cert that was signed by our (very old) internal CA cert that contains an MD5 signature algorithm. This is causing problems with some of our SPs who are trying to validate the cert. I have been unable to convince said SPs that they do not need to validate.<br><br>So, my question is: If I generate a new self-signed IdP signing cert using the existing IdP signing key, then drop that new cert into our metadata, will SPs who have the old metadata continue to work? Obviously we'd be distributing the new metadata to our SPs as quickly as possible, but the process will take some time.<br><br>Follow up question: Is there a "best practice" for what key length and digest hashing algorithm to use for an IdP signing cert? I'm guessing 2048 and sha256 are the minimum, but will going to 4096 and sha512 likely cause interoperability issues with some SPs?<br><div><br></div><div>Thank you in advance,</div><div>-Brian</div><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><font face="arial, sans-serif"><br></font></div></div></div></div></div>