<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Did shibboleth.DefaultSecurityConfiguration change in 4.1? I can't get this work. I have in credentials.xml:</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<util:list id="shibboleth.SigningCredentials">
<div> <ref bean="shibboleth.DefaultSigningCredential" /></div>
<div> <ref bean="shibboleth.OldSigningCredential" /></div>
<div> </util:list></div>
<div><br>
</div>
<div> <!-- Your IdP's default signing key, set via property file. --></div>
<div> <bean id="shibboleth.DefaultSigningCredential"</div>
<div> class="net.shibboleth.idp.profile.spring.factory.BasicX509CredentialFactoryBean"</div>
<div> p:privateKeyResource="%{idp.signing.key}"</div>
<div> p:certificateResource="%{idp.signing.cert}"</div>
<div> p:entityId-ref="entityID" /></div>
<div><br>
</div>
<div> <bean id="shibboleth.OldSigningCredential"</div>
<div> class="net.shibboleth.idp.profile.spring.factory.BasicX509CredentialFactoryBean"</div>
<div> p:privateKeyResource="%{idp.signing.key.2}"</div>
<div> p:certificateResource="%{idp.signing.cert.2}"</div>
p:entityId-ref="entityID" /><br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
in relying-party.xml</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<bean id="OldSigningCredentialConfig" parent="shibboleth.DefaultSecurityConfiguration">
<div> <property name="signatureSigningConfiguration"></div>
<div> <bean parent="shibboleth.SigningConfiguration.SHA256" p:signingCredentials-ref="shibboleth.OldSigningCredential" /></div>
<div> </property></div>
</bean><br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<bean parent="RelyingPartyByName" c:relyingPartyIds="#{{'https://jostle.us'}}">
<div> <property name="profileConfigurations"></div>
<div> <list></div>
<div> <bean parent="Shibboleth.SSO" p:securityConfiguration-ref="OldSigningCredentialConfig" /></div>
<div> <bean parent="SAML2.SSO" p:disallowedFeatures-ref="SAML2.SSO.FEATURE_AUTHNCONTEXT"></div>
<div> <property name="defaultAuthenticationMethods"></div>
<div> <list></div>
<div> <ref bean="MFASAML2Principal" /></div>
<div> </list></div>
<div> </property></div>
<div> </bean></div>
<div> </list></div>
<div> </property></div>
</bean><br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
The application should work with <span style="background-color:rgb(255, 255, 255);display:inline !important">shibboleth.OldSigningCredential. No ERR and it works fine using the other key on the production server which doesn't have these changes.</span></div>
<div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div id="Signature">
<div>
<div></div>
<div id="divtagdefaultwrapper" style="font-size:12pt; color:#000000; background-color:#FFFFFF; font-family:Calibri,Arial,Helvetica,sans-serif">
<div style="font-family:Tahoma; font-size:13px">---
<div><span id="ms-rterangepaste-start"></span><span style="font-family:arial,helvetica,sans-serif; font-size:13px; line-height:16.003px">Roberto Ullfig - rullfig@uic.edu</span><br style="font-family:arial,helvetica,sans-serif; font-size:13px; line-height:16.003px">
<span style="font-family:arial,helvetica,sans-serif; font-size:13px; line-height:16.003px">Systems Administrator</span><br style="font-family:arial,helvetica,sans-serif; font-size:13px; line-height:16.003px">
<span style="font-family:arial,helvetica,sans-serif; font-size:13px; line-height:16.003px">Enterprise Applications & Services | Technology Solutions</span><br style="font-family:arial,helvetica,sans-serif; font-size:13px; line-height:16.003px">
<span style="font-family:arial,helvetica,sans-serif; font-size:13px; line-height:16.003px">University of Illinois - Chicago</span>
<div><span id="ms-rterangepaste-end"></span></div>
</div>
</div>
</div>
</div>
</div>
</div>
<div id="appendonsend"></div>
<hr style="display:inline-block;width:98%" tabindex="-1">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" style="font-size:11pt" color="#000000"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Cantor, Scott <cantor.2@osu.edu><br>
<b>Sent:</b> Tuesday, June 29, 2021 4:15 PM<br>
<b>To:</b> Shib Users <users@shibboleth.net><br>
<b>Subject:</b> Re: Question about relying-party-system.xml</font>
<div> </div>
</div>
<div class="BodyFragment"><font size="2"><span style="font-size:11pt;">
<div class="PlainText">On 6/29/21, 5:00 PM, "users on behalf of Ullfig, Roberto Alfredo" <users-bounces@shibboleth.net on behalf of rullfig@uic.edu> wrote:<br>
<br>
> Yes we are on IDP 4.1. Where can I see shibboleth.DefaultSecurityConfiguration etc now?<br>
<br>
In the source, I'll have to update the page when I have a chance.<br>
<br>
> Also, I just noticed that idp.properties is set to the default cert hash:<br>
<br>
That has nothing to do with any certificates, that's the digest algorithm used when signing XML.<br>
<br>
-- Scott<br>
<br>
<br>
-- <br>
For Consortium Member technical support, see <a href="https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwiki.shibboleth.net%2Fconfluence%2Fx%2FcoFAAg&data=04%7C01%7Crullfig%40uic.edu%7Cfbb28afb493040dc418208d93b43064b%7Ce202cd477a564baa99e3e3b71a7c77dd%7C0%7C0%7C637605981340847527%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=LwzFDb4l09qk5NVcnh0VfRIy5vPyKbC73Efz2g7q%2FG4%3D&reserved=0">
https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwiki.shibboleth.net%2Fconfluence%2Fx%2FcoFAAg&data=04%7C01%7Crullfig%40uic.edu%7Cfbb28afb493040dc418208d93b43064b%7Ce202cd477a564baa99e3e3b71a7c77dd%7C0%7C0%7C637605981340847527%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=LwzFDb4l09qk5NVcnh0VfRIy5vPyKbC73Efz2g7q%2FG4%3D&reserved=0</a><br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div>
</span></font></div>
</body>
</html>