I wonder if this is a needed area for improvement.  Is that true?  

I'm sure I'm not the only one dealing with cert rotations not being 
automatic in CAS but it is widely mentioned with SPs that use short life 
certificates.

On Friday, November 12, 2021 at 9:07:17 AM UTC-6 Andrew Marker wrote:

> Hi all,
>
> Is there a way to maintain the dynamic pull of the metadata and for a 
> service or collectively for all SP MD files such that it does not fail when 
> the certs are expired but an alternate cert is present?  I think because of 
> cert rotation, this is a situation that can occur.
>
> ----
>
> I recently migrated our InCommon (IC) Federation to CAS and generally 
> speaking it is working well.
>
> I have an IC vendor who has 2 keys (neither identified by use) and I had 
> set up a service in CAS to dynamically pull the SP MD from InCommon.
>   * One of the keys expired in 2013
>   * One key expires in the future
>
> CAS rejects the auth request when it finds the expired cert instead of 
> skipping and finding the other cert.  The only way I could get around this 
> was to:
>   * download a copy of the metadata
>   * remove the expired cert
>   * remove the life time attribute for the METADATA pushed by InCommon on 
> the copy.
>   * store it and reference the copy for use
>
> https://mdq.incommon.org/entities/https%3A%2F%2Fe5.onthehub.com
>
> Is there abetter way to maintain the dynamic pull of the metadata and for 
> this service or collectively for all SP MD file not fail when the certs are 
> expired?
>

-- 
- Website: https://apereo.github.io/cas
- Gitter Chatroom: https://gitter.im/apereo/cas
- List Guidelines: https://goo.gl/1VRrw7
- Contributions: https://goo.gl/mh7qDG
--- 
You received this message because you are subscribed to the Google Groups "CAS 
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/a/apereo.org/d/msgid/cas-user/a970f39c-7fd2-4ace-b1ad-f6a6b8ee465en%40apereo.org.

Reply via email to