<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=Windows-1252">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
That is a good point about the non-Shibboleth SPs.</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
We changed our certificate recently. The first thing we did was identify all ACTIVE service providers by searching our logs over the course of a 3 month period. We put all this information in a spreadsheet and then started extracting all the contact information
 from the metadata (adding that to the sheet as well). We had a script that would parse metadata repositories looking for contact information etc... For those service providers without valid contact information we had to investigate on a case by case basis
 - we had about 200 active service providers as I recall. We also collected application URLs and saved that information as well. Then we sent out a few directed mailings to all the contacts over the course of a few months with instructions on what they had
 to do. Using a development IDP server configured with the new certificate we were able to test many of the applications before we made the change and kept track of that in our spreadsheet. There were maybe a dozen SPs still broken when the change was made
 but they were all sorted out within a week or so. For SPs that support multiple certificates, the transition was seamless. For some SPs we coordinated with their service technicians on the day of the changeover.</div>
<div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div id="Signature">
<div>
<div></div>
<div id="divtagdefaultwrapper" style="font-size:12pt; color:#000000; background-color:#FFFFFF; font-family:Calibri,Arial,Helvetica,sans-serif">
<div style="font-family:Tahoma; font-size:13px">---
<div><span id="ms-rterangepaste-start"></span><span style="font-family:arial,helvetica,sans-serif; font-size:13px; line-height:16.003px">Roberto Ullfig - rullfig@uic.edu</span><br style="font-family:arial,helvetica,sans-serif; font-size:13px; line-height:16.003px">
<span style="font-family:arial,helvetica,sans-serif; font-size:13px; line-height:16.003px">Systems Administrator</span><br style="font-family:arial,helvetica,sans-serif; font-size:13px; line-height:16.003px">
<span style="font-family:arial,helvetica,sans-serif; font-size:13px; line-height:16.003px">Enterprise Applications & Services | Technology Solutions</span><br style="font-family:arial,helvetica,sans-serif; font-size:13px; line-height:16.003px">
<span style="font-family:arial,helvetica,sans-serif; font-size:13px; line-height:16.003px">University of Illinois - Chicago</span>
<div><span id="ms-rterangepaste-end"></span></div>
</div>
</div>
</div>
</div>
</div>
</div>
<div id="appendonsend"></div>
<hr style="display:inline-block;width:98%" tabindex="-1">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" style="font-size:11pt" color="#000000"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Wessel, Keith via users <users@shibboleth.net><br>
<b>Sent:</b> Friday, June 3, 2022 11:18 AM<br>
<b>To:</b> Shib Users <users@shibboleth.net><br>
<b>Cc:</b> Wessel, Keith W (UIUC) <kwessel@illinois.edu><br>
<b>Subject:</b> RE: Expiring IDP signing certificate</font>
<div> </div>
</div>
<style>
<!--
@font-face
        {font-family:"Cambria Math"}
@font-face
        {font-family:Calibri}
@font-face
        {font-family:Tahoma}
p.x_MsoNormal, li.x_MsoNormal, div.x_MsoNormal
        {margin:0in;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif}
a:link, span.x_MsoHyperlink
        {color:#0563C1;
        text-decoration:underline}
p.x_xmsonormal, li.x_xmsonormal, div.x_xmsonormal
        {margin:0in;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif}
span.x_EmailStyle23
        {font-family:"Calibri",sans-serif;
        color:windowtext}
.x_MsoChpDefault
        {font-size:10.0pt}
@page WordSection1
        {margin:1.0in 1.0in 1.0in 1.0in}
div.x_WordSection1
        {}
-->
</style>
<div lang="EN-US" link="#0563C1" vlink="#954F72" style="word-wrap:break-word">
<div class="x_WordSection1">
<p class="x_MsoNormal">Shibboleth SPs won’t care if it expires. That can’t be said to be true for all SAML implementations and vendors.</p>
<p class="x_MsoNormal"> </p>
<p class="x_MsoNormal">And even though nothing will break, it’s high advisable to not have an expired certificate published wit your InCommon metadata.</p>
<p class="x_MsoNormal"> </p>
<p class="x_MsoNormal">Keith</p>
<p class="x_MsoNormal"> </p>
<p class="x_MsoNormal"> </p>
<div>
<div style="border:none; border-top:solid #E1E1E1 1.0pt; padding:3.0pt 0in 0in 0in">
<p class="x_MsoNormal"><b>From:</b> users <users-bounces@shibboleth.net> <b>On Behalf Of
</b>Ullfig, Roberto Alfredo via users<br>
<b>Sent:</b> Friday, June 3, 2022 11:16 AM<br>
<b>To:</b> Shib Users <users@shibboleth.net><br>
<b>Cc:</b> Ullfig, Roberto A (UIC) <rullfig@uic.edu><br>
<b>Subject:</b> Re: Expiring IDP signing certificate</p>
</div>
</div>
<p class="x_MsoNormal"> </p>
<div>
<p class="x_MsoNormal"><span style="font-size:12.0pt; color:black">If you google for "replacing IDP cert incommon" you will get some hits to useful documentation but those sites are currently unavailable. As I understand it though, that certificate expiration
 date is entirely advisory, nothing should break or change when that self-signed certificate expires. The expiration date is merely advising that you should periodically replace the certificate.</span></p>
</div>
<div>
<div>
<p class="x_MsoNormal"><span style="font-size:12.0pt; color:black"> </span></p>
</div>
<div id="x_Signature">
<div>
<div id="x_divtagdefaultwrapper">
<div>
<p class="x_MsoNormal" style="background:white"><span style="font-size:10.0pt; font-family:"Tahoma",sans-serif; color:black">---
</span></p>
<div>
<p class="x_MsoNormal" style="background:white"><span style="font-size:10.0pt; font-family:"Arial",sans-serif; color:black">Roberto Ullfig -
<a href="mailto:rullfig@uic.edu">rullfig@uic.edu</a><br>
Systems Administrator<br>
Enterprise Applications & Services | Technology Solutions<br>
University of Illinois - Chicago</span><span style="font-size:10.0pt; font-family:"Tahoma",sans-serif; color:black">
</span></p>
</div>
</div>
</div>
</div>
</div>
</div>
<div class="x_MsoNormal" align="center" style="text-align:center">
<hr size="2" width="98%" align="center">
</div>
<div id="x_divRplyFwdMsg">
<p class="x_MsoNormal"><b><span style="color:black">From:</span></b><span style="color:black"> users <<a href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a>> on behalf of Ho, PeiQuan via users <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>><br>
<b>Sent:</b> Friday, June 3, 2022 10:51 AM<br>
<b>To:</b> <a href="mailto:users@shibboleth.net">users@shibboleth.net</a> <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>><br>
<b>Cc:</b> Ho, PeiQuan <<a href="mailto:PeiQuan.Ho@tufts.edu">PeiQuan.Ho@tufts.edu</a>><br>
<b>Subject:</b> Expiring IDP signing certificate</span> </p>
<div>
<p class="x_MsoNormal"> </p>
</div>
</div>
<div>
<div>
<p class="x_xmsonormal">Hi,</p>
<p class="x_xmsonormal"> </p>
<p class="x_xmsonormal">  Our IDP signing certificate as used in shibboleth.DefaultSigningCredential is expiring.  It is the 10-year self-signed certificate as recommended during installation.  What is the process to update/rollover this cert with minimal impact
 to SPs?</p>
<p class="x_xmsonormal"> </p>
<p class="x_xmsonormal">Thanks,</p>
<p class="x_xmsonormal">-PQ</p>
<p class="x_xmsonormal"> </p>
</div>
</div>
</div>
</div>
</body>
</html>