Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

  1. Add a new <md:KeyDescriptor use="signing"> element to IdP metadata.
  2. Wait for the newly updated metadata to propagate throughout the Federation. Two weeks is safe, although longer times may be needed, depending on the operational practices of your partners.
  3. Configure the IdP software to use the new key (instead of the old key) as the signing key and/or back-channel TLS key.
  4. Remove the old <md:KeyDescriptor use="signing"> element from IdP metadata.

...