SAML specify signing cert/key

98 views
Skip to first unread message

atilling

unread,
Jan 31, 2024, 12:32:23 PM1/31/24
to CAS Community
We're trying to move from shibboleth/cas to just cas with cas as the saml provider. We want to have as little downtime so I'm trying to have cas using the same signing and encryption keys as the shibboleth server. 

I've been over the documentation for the IDP and I'm not seeing how to specify the cert or where CAS generates it from if it's being generated.

Is there a property to specify the cert/key pair for signing?

atilling

unread,
Jan 31, 2024, 11:49:51 PM1/31/24
to CAS Community, atilling
Using the property 
cas.authn.saml-idp.metadata.file-system.location=file:/etc/cas/saml/idp

I can get cas to export the idp-signing cert and key that it's using, but is it there a way to swap that so I can update the idp-singing.crt/key and cas imports them?

atilling

unread,
Feb 1, 2024, 2:56:02 PM2/1/24
to CAS Community, atilling
Even tried the instructions here https://fawnoos.com/2019/12/16/cas62x-saml2-metadata-service/ to set a service specific signing key pair and it's still using a cert that doesn't appear in any idp_signing file.

Ray Bon

unread,
Feb 1, 2024, 2:56:02 PM2/1/24
to cas-...@apereo.org, atil...@conncoll.edu
Cas creates metadata and certs when they do not exist.
Create them and put them in that directory and cas will use your files.

Ray


On Wed, 2024-01-31 at 13:35 -0800, atilling wrote:
Notice: This message was sent from outside the University of Victoria email system. Please be cautious with links and sensitive information.

atilling

unread,
Feb 2, 2024, 1:42:16 PM2/2/24
to CAS Community, Ray Bon, atil...@conncoll.edu
Seems to be pulling them in now, thank you

Ray Bon

unread,
Feb 2, 2024, 9:57:11 PM2/2/24
to cas-...@apereo.org, atil...@conncoll.edu


On Thu, 2024-02-01 at 10:45 -0800, atilling wrote:
Notice: This message was sent from outside the University of Victoria email system. Please be cautious with links and sensitive information.

Reply all
Reply to author
Forward
0 new messages