Forum Discussion
SAML External IDP key roll-over
Hi,
One of our external IDP connectors is implementing a new certificate for the Assertion Verification. They provided new metadata which contains two certificates, the current one and the new future one.
But in the certificate settings I can only select one certificate. Is there any key roll-over functionality in APM, or do we have to switch the certificate manually when they change it?
Cheers, Jens
- youssef1
Cumulonimbus
Hi jens,
In your side you have to use only the new one.
The IDP maintain both because it will allow to migrate smoothly.
You can create an bundle in F5, just go to (System ›› Certificate Management : Traffic Certificate Management : SSL Certificate List), then create a new cert and paste both certificate. call it bundle IDP.
then set this bundle in your External IDP profile.
Hope it's clear. keep me in touch.
Regards
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com