Skip to Content.
Sympa Menu

metadata-support - Re: [Metadata-Support] Re: [InC] Moving my IDP to new server with new Metadata

Subject: InCommon metadata support

List archive

Re: [Metadata-Support] Re: [InC] Moving my IDP to new server with new Metadata


Chronological Thread 
  • From: "Cantor, Scott" <>
  • To: "" <>
  • Subject: Re: [Metadata-Support] Re: [InC] Moving my IDP to new server with new Metadata
  • Date: Fri, 28 Aug 2015 14:54:09 +0000
  • Accept-language: en-US
  • Authentication-results: spf=temperror (sender IP is 164.107.81.214) smtp.mailfrom=osu.edu; incommon.org; dkim=none (message not signed) header.d=none;incommon.org; dmarc=temperror action=none header.from=osu.edu;
  • Spamdiagnosticmetadata: NSPM
  • Spamdiagnosticoutput: 1:23

On 8/28/15, 10:41 AM,
"
on behalf of Esquivel, Vince"
<
on behalf of
>
wrote:

>By key, do you mean the signing cert that we upload to the InCommon profile?

The signing certificate for the IdP, yes.

>Are we not able to have two certs on in InCommon profile?

Sure. That doesn't help with all the other SPs that don't support metadata.

You will generally have to configure a bunch of relying party overrides and
schedule specific times to change the key for those SPs. They will in some
cases not support multiple signing keys either, making the change a flag day
for any given RP with that limitation.

-- Scott




Archive powered by MHonArc 2.6.16.

Top of Page