<div dir="ltr">Hello, <br><br>I would like to get some idea if it's possible to have my IDP with multiple cert? <br>Meaning... it's more like federation metadata but there will be just two sets of idp-signing and idp-encryption keys in my metadata. <br><br>Reason behind this request: I would like to give my customers little comfort when it's IDP's cert renewal ( shibboleth cert and key ) time. Right now they need to call a downtime and need concrete real time communication with all affiliated SPs when IDP renew their cert. <br><br>Instead I was thinking like what if I could allow them to have two sets of cert ( one set is that which is going to expire and another one is renewed one ). In that way... they could only inform SPs to refresh IDP's metadata and there won't be any downtime as well; because expired cert and renewed cert both are in the same metadata. <br clear="all"><div><br></div>-- <br><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature">Best,<br>Zico</div></div>