Hi all,

Is there a way to maintain the dynamic pull of the metadata and for a 
service or collectively for all SP MD files such that it does not fail when 
the certs are expired but an alternate cert is present?  I think because of 
cert rotation, this is a situation that can occur.

----

I recently migrated our InCommon (IC) Federation to CAS and generally 
speaking it is working well.

I have an IC vendor who has 2 keys (neither identified by use) and I had 
set up a service in CAS to dynamically pull the SP MD from InCommon.
  * One of the keys expired in 2013
  * One key expires in the future

CAS rejects the auth request when it finds the expired cert instead of 
skipping and finding the other cert.  The only way I could get around this 
was to:
  * download a copy of the metadata
  * remove the expired cert
  * remove the life time attribute for the METADATA pushed by InCommon on 
the copy.
  * store it and reference the copy for use

https://mdq.incommon.org/entities/https%3A%2F%2Fe5.onthehub.com

Is there abetter way to maintain the dynamic pull of the metadata and for 
this service or collectively for all SP MD file not fail when the certs are 
expired?

-- 
- Website: https://apereo.github.io/cas
- Gitter Chatroom: https://gitter.im/apereo/cas
- List Guidelines: https://goo.gl/1VRrw7
- Contributions: https://goo.gl/mh7qDG
--- 
You received this message because you are subscribed to the Google Groups "CAS 
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/a/apereo.org/d/msgid/cas-user/3135deb7-039a-4cb8-9643-3f305b40f589n%40apereo.org.

Reply via email to