Forum Discussion

Jens_Deprez_133's avatar
Jens_Deprez_133
Icon for Nimbostratus rankNimbostratus
Jun 01, 2018

SAML External IDP key roll-over

Hi,

 

One of our external IDP connectors is implementing a new certificate for the Assertion Verification. They provided new metadata which contains two certificates, the current one and the new future one.

 

But in the certificate settings I can only select one certificate. Is there any key roll-over functionality in APM, or do we have to switch the certificate manually when they change it?

 

Cheers, Jens

 

1 Reply

  • Hi jens,

     

    In your side you have to use only the new one.

     

    The IDP maintain both because it will allow to migrate smoothly.

     

    You can create an bundle in F5, just go to (System ›› Certificate Management : Traffic Certificate Management : SSL Certificate List), then create a new cert and paste both certificate. call it bundle IDP.

     

    then set this bundle in your External IDP profile.

     

    Hope it's clear. keep me in touch.

     

    Regards