<div dir="ltr"><div class="gmail_default" style="font-family:trebuchet ms,sans-serif;font-size:small;color:#073763">I have an old campus SP that I wanted to start publishing via InCommon before switching it over to using our Cirrus social login proxy. The SP has an expired cert. Federation Manager said no. I was sad. But I got over it. -Les</div><div><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><br></div><div><table style="color:rgb(136,136,136);border:none;border-collapse:collapse"><tbody><tr style="height:0pt;border-top:1pt solid rgb(204,204,204)"><td style="border-right:1pt solid rgb(204,204,204);vertical-align:middle;padding:5pt;overflow:hidden"><p dir="ltr" style="line-height:1.2;margin-top:0pt;margin-bottom:0pt"><a href="http://www.carleton.edu/" target="_blank"><span style="font-size:11pt;font-family:Arial;color:rgb(17,85,204);vertical-align:baseline;white-space:pre-wrap"><span style="border:none;display:inline-block;overflow:hidden;width:70px;height:73px"><img height="73" src="https://lh6.googleusercontent.com/QEL1To3Ci_dJA1huaKzfZ0Lf4MaZlAy_f-W3vQjbyzNq_yXq_ZYGv3tuT4dkaZS_bZ5X6fZR4iKzBboZhxbCF5htZFnLNKGqmrzHsVJtsjsy0pfK5w2z0Dlq-EtZcWhv0PxBpWmR" width="70" style="margin-left:0px;margin-top:0px"></span></span></a></p></td><td style="border-left:1pt solid rgb(204,204,204);vertical-align:top;padding:10.8pt;overflow:hidden"><p dir="ltr" style="line-height:1.38;margin-top:0pt;margin-bottom:0pt"><font color="#dea410" face="Arial"><span style="font-size:14.6667px;white-space:pre-wrap"><b>Les LaCroix '79</b></span></font></p><p dir="ltr" style="line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style="color:rgb(11,80,145)"><span style="font-size:11pt;font-family:Arial;vertical-align:baseline;white-space:pre-wrap">Strategic Technologist</span></span></p><p dir="ltr" style="line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style="color:rgb(11,80,145)"><span style="font-size:11pt;font-family:Arial;vertical-align:baseline;white-space:pre-wrap">Information Technology Services</span></span></p><p dir="ltr" style="line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style="color:rgb(11,80,145)"><span style="font-size:11pt;font-family:Arial;vertical-align:baseline;white-space:pre-wrap">t: (507) 222-5455</span></span></p></td></tr></tbody></table></div></div></div></div><br></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Fri, Jun 3, 2022 at 11:18 AM Wessel, Keith via users <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
<div lang="EN-US" style="overflow-wrap: break-word;">
<div class="gmail-m_1920927782964019WordSection1">
<p class="MsoNormal">Shibboleth SPs won’t care if it expires. That can’t be said to be true for all SAML implementations and vendors.<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">And even though nothing will break, it’s high advisable to not have an expired certificate published wit your InCommon metadata.<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">Keith<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<div>
<div style="border-right:none;border-bottom:none;border-left:none;border-top:1pt solid rgb(225,225,225);padding:3pt 0in 0in">
<p class="MsoNormal"><b>From:</b> users <<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a>> <b>On Behalf Of
</b>Ullfig, Roberto Alfredo via users<br>
<b>Sent:</b> Friday, June 3, 2022 11:16 AM<br>
<b>To:</b> Shib Users <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>><br>
<b>Cc:</b> Ullfig, Roberto A (UIC) <<a href="mailto:rullfig@uic.edu" target="_blank">rullfig@uic.edu</a>><br>
<b>Subject:</b> Re: Expiring IDP signing certificate<u></u><u></u></p>
</div>
</div>
<p class="MsoNormal"><u></u> <u></u></p>
<div>
<p class="MsoNormal"><span style="font-size:12pt;color:black">If you google for "replacing IDP cert incommon" you will get some hits to useful documentation but those sites are currently unavailable. As I understand it though, that certificate expiration
date is entirely advisory, nothing should break or change when that self-signed certificate expires. The expiration date is merely advising that you should periodically replace the certificate.<u></u><u></u></span></p>
</div>
<div>
<div>
<p class="MsoNormal"><span style="font-size:12pt;color:black"><u></u> <u></u></span></p>
</div>
<div id="gmail-m_1920927782964019Signature">
<div>
<div id="gmail-m_1920927782964019divtagdefaultwrapper">
<div>
<p class="MsoNormal" style="background:white"><span style="font-size:10pt;font-family:Tahoma,sans-serif;color:black">---
<u></u><u></u></span></p>
<div>
<p class="MsoNormal" style="background:white"><span style="font-size:10pt;font-family:Arial,sans-serif;color:black">Roberto Ullfig -
<a href="mailto:rullfig@uic.edu" target="_blank">rullfig@uic.edu</a><br>
Systems Administrator<br>
Enterprise Applications & Services | Technology Solutions<br>
University of Illinois - Chicago</span><span style="font-size:10pt;font-family:Tahoma,sans-serif;color:black">
<u></u><u></u></span></p>
</div>
</div>
</div>
</div>
</div>
</div>
<div class="MsoNormal" align="center" style="text-align:center">
<hr size="2" width="98%" align="center">
</div>
<div id="gmail-m_1920927782964019divRplyFwdMsg">
<p class="MsoNormal"><b><span style="color:black">From:</span></b><span style="color:black"> users <<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a>> on behalf of Ho, PeiQuan via users <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>><br>
<b>Sent:</b> Friday, June 3, 2022 10:51 AM<br>
<b>To:</b> <a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a> <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>><br>
<b>Cc:</b> Ho, PeiQuan <<a href="mailto:PeiQuan.Ho@tufts.edu" target="_blank">PeiQuan.Ho@tufts.edu</a>><br>
<b>Subject:</b> Expiring IDP signing certificate</span> <u></u><u></u></p>
<div>
<p class="MsoNormal"> <u></u><u></u></p>
</div>
</div>
<div>
<div>
<p class="gmail-m_1920927782964019xmsonormal">Hi,<u></u><u></u></p>
<p class="gmail-m_1920927782964019xmsonormal"> <u></u><u></u></p>
<p class="gmail-m_1920927782964019xmsonormal"> Our IDP signing certificate as used in shibboleth.DefaultSigningCredential is expiring. It is the 10-year self-signed certificate as recommended during installation. What is the process to update/rollover this cert with minimal impact
to SPs?<u></u><u></u></p>
<p class="gmail-m_1920927782964019xmsonormal"> <u></u><u></u></p>
<p class="gmail-m_1920927782964019xmsonormal">Thanks,<u></u><u></u></p>
<p class="gmail-m_1920927782964019xmsonormal">-PQ<u></u><u></u></p>
<p class="gmail-m_1920927782964019xmsonormal"> <u></u><u></u></p>
</div>
</div>
</div>
</div>
-- <br>
For Consortium Member technical support, see <a href="https://shibboleth.atlassian.net/wiki/x/ZYEpPw" rel="noreferrer" target="_blank">https://shibboleth.atlassian.net/wiki/x/ZYEpPw</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>