Groups
Groups
Sign in
Groups
Groups
CAS Community
Conversations
About
Send feedback
Help
Rolling over IdP SAML 2.0 certs
79 views
Skip to first unread message
Patryk Sondej
unread,
Aug 12, 2024, 8:14:19 AM
8/12/24
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to CAS Community
Is rollover IdP SAML 2.0 certs supported in CAS?
Eg. primary (old) + secondary (new)
Can't find anything in documentation.
Matthew Gordon
unread,
Aug 16, 2024, 4:07:57 PM
8/16/24
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to CAS Community, Patryk Sondej
Sorry I can't help, but I am also interested in this, if anyone has any ideas?
Thank you,
Matt
Ray Bon
unread,
Aug 25, 2024, 1:11:05 PM
8/25/24
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to cas-...@apereo.org
Patryk,
If you have a dev environment, you can check this. Maybe cat the old and new keys/certs into idp-signing.{key,crt}
Ray
On Mon, 2024-08-12 at 03:33 -0700, Patryk Sondej wrote:
You don't often get email from
bux.p...@gmail.com
.
Learn why this is important
Matthew Gordon
unread,
Oct 23, 2025, 11:24:04 AM (2 days ago)
Oct 23
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to CAS Community
Hello,
Did this actually work, or is there a recommended solution?
Thank you,
Matt
Matthew Gordon
unread,
Oct 24, 2025, 10:06:45 AM (yesterday)
Oct 24
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to CAS Community, Matthew Gordon
There is a per service option that seems to work:
https://apereo.github.io/cas/7.3.x/installation/Configuring-SAML2-DynamicMetadata.html#per-service
The SAML response still appears to have the default IdP cert in it, but the SP needs the updated metadata certificate to function... I put new metadata, cert, and key in the above directory.
Thank you,
Matt
Reply all
Reply to author
Forward
0 new messages