<div dir="ltr">"they have an IDP signing certificate that was issued by the old CA, and either the signing cert or the CA cert (or both) used an MD5 signature. Is that correct?"<div><br></div><div>Our IdP signing cert has an sha1 signature, but was signed by an internal CA with an MD5 signature.</div><div><br></div><div>"Is it possible to generate a new, self-signed cert using a modern signing algorithm such as SHA-256 from the same private key? If so, won't data signed/encrypted with the private key still be able to be validated/decrypted by the SP which has the new cert?"</div><div><br></div><div>I'm sure SPs that have the new cert generated from the original private key will work, but what I was hoping for is that SPs that have the *old* cert would also continue to work.</div><div>And I guess the answer is maybe? Depends on the SP software being used and the processes in place at the SP...</div><div><br></div><div>Thanks,</div><div>-Brian</div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Thu, Jan 21, 2021 at 11:14 AM Andrew Jason Morgan <<a href="mailto:morgan@oregonstate.edu" target="_blank">morgan@oregonstate.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
<div dir="ltr">
<div style="font-family:Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
I want to understand this better...</div>
<div style="font-family:Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
I think Brian says that they have an IDP signing certificate that was issued by the old CA, and either the signing cert or the CA cert (or both) used an MD5 signature. Is that correct?</div>
<div style="font-family:Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
Is it possible to generate a new, self-signed cert using a modern signing algorithm such as SHA-256 from the same private key? If so, won't data signed/encrypted with the private key still be able to be validated/decrypted by the SP which has the new cert?</div>
<div style="font-family:Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
Thanks,</div>
<div style="font-family:Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
Andy<br>
</div>
<div>
<div id="gmail-m_7124592275592423891gmail-m_5691358931878164743appendonsend"></div>
<div style="font-family:Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<br>
</div>
<hr style="display:inline-block;width:98%">
<div id="gmail-m_7124592275592423891gmail-m_5691358931878164743divRplyFwdMsg" dir="ltr"><font style="font-size:11pt" face="Calibri, sans-serif" color="#000000"><b>From:</b> users <<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a>> on behalf of Cantor, Scott <<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>><br>
<b>Sent:</b> Thursday, January 21, 2021 9:58 AM<br>
<b>To:</b> Shib Users <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>><br>
<b>Subject:</b> Re: IdP Signing Certificate question</font>
<div> </div>
</div>
<div><font size="2"><span style="font-size:11pt">
<div>[This email originated from outside of OSU. Use caution with links and attachments.]<br>
<br>
On 1/21/21, 12:52 PM, "users on behalf of Brian Biggs" <<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a> on behalf of <a href="mailto:biggsb@sonoma.edu" target="_blank">biggsb@sonoma.edu</a>> wrote:<br>
<br>
> Just to be clear, what I'm hearing is that keeping our private key and changing our public key doesn't buy us anything as<br>
> far as keeping SPs working during a transition. Is that right?<br>
<br>
You can't change one and not the other. You're confusing a new certificate with a new public key, that's not how it works. The keypair is a unit. Issuing a new certificate for the same public key is what you're talking about.<br>
<br>
It buys a lot, but nothing is universal. Whether that's enough is subjective. I have never been faced with the question but no, you cannot just reissue it. That's going to break plenty of stuff. Just much less than changing the key.<br>
<br>
> So we might as well generate new public and private keys and work on a coordinated cutover with all our SPs...<br>
<br>
If you're going to do that, then the result at the end should be:<br>
<br>
- A key protected in such a way that the chances of anything short of outright compromise of server memory should not cause it to be at risk. To me that means it should not be accessible on disk at runtime or ever backed up outside of a very controlled process.<br>
<br>
- A tagging/metadata-based strategy for controlling the key used by all broken services so that a future change can be automated for all the non-broken services and the broken ones controlled on an individual basis.<br>
<br>
Such a nightmarish task has to lead to very tangible benefits to be worthwhile.<br>
<br>
-- Scott<br>
<br>
<br>
--<br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" target="_blank">
https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</div>
</span></font></div>
</div>
</div>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div><br clear="all"><div><br></div>-- <br><div dir="ltr"><div dir="ltr"><font face="arial, sans-serif">Lead Identity Mgmt/Systems Integration<br>Information Technology<br>Sonoma State University</font><div><font face="arial, sans-serif"><br></font></div></div></div>