PUBLIC / CYHOEDDUS Thanks for the heads up Ray, We will now remove the expiring Azure certificate shortly after successfully testing the rollover, and use the /cas/sp/idp/metadata?force=true endpoint on our CAS server whenever our Azure service’s metadata changes. Kevin
From: cas-user@apereo.org <cas-user@apereo.org> on behalf of Ray Bon <r...@uvic.ca> Date: Thursday, 30 March 2023 at 18:23 To: cas-user@apereo.org <cas-user@apereo.org> Subject: Re: [cas-user] CAS, Azure and expiring SAML cert - any issues? Kevin, Here is an example of cert rollover, https://www.switch.ch/aai/guides/idp/certificate-rollover/<https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.switch.ch%2Faai%2Fguides%2Fidp%2Fcertificate-rollover%2F&data=05%7C01%7Ckevin.sewell%40southwales.ac.uk%7C696a3021f54a4aa6c50d08db314383f5%7Ce5aafe7c971b4ab7b039141ad36acec0%7C0%7C0%7C638157938272059800%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=95QF7gu9QygNqDWdf%2BM2bhRx56mm4n0H6ezpIUZOdYM%3D&reserved=0> The expired certs will prevent log in if the applications are not broken. Ray On Thu, 2023-03-30 at 15:54 +0000, 'Kevin Sewell' via CAS Community wrote: Notice: This message was sent from outside the University of Victoria email system. Please be cautious with links and sensitive information. PUBLIC / CYHOEDDUS Hi, We are delegating our CAS authentication to Azure via SAML using cas.authn.pac4j.saml. We've been doing that for 3 years, without any issues. Our Azure CAS app's SAML certificate is due to expire shortly. We are planning to renew the certificate, make it active, and delete the expired one once it actually becomes expired. Can I ask whether anyone has had issues after creating a new certificate for your CAS app in Azure and making it Active? Also, do you know whether it was actually necessary to renew the certificate or did it just carry on without issues? Currently running v6.5, but would appreciate your experience with any version. Many thanks! Kevin -- - Website: https://apereo.github.io/cas<https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fapereo.github.io%2Fcas&data=05%7C01%7Ckevin.sewell%40southwales.ac.uk%7C696a3021f54a4aa6c50d08db314383f5%7Ce5aafe7c971b4ab7b039141ad36acec0%7C0%7C0%7C638157938272059800%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=ORlzGVw5iCt1DsAaIGJmJwpF0EI7GQi5ndwunhsPpjs%3D&reserved=0> - Gitter Chatroom: https://gitter.im/apereo/cas<https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgitter.im%2Fapereo%2Fcas&data=05%7C01%7Ckevin.sewell%40southwales.ac.uk%7C696a3021f54a4aa6c50d08db314383f5%7Ce5aafe7c971b4ab7b039141ad36acec0%7C0%7C0%7C638157938272059800%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=9emczCQMJBdrhNrO%2FGm2nP4IeftTaez8dS6GymXuDMw%3D&reserved=0> - List Guidelines: https://goo.gl/1VRrw7<https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgoo.gl%2F1VRrw7&data=05%7C01%7Ckevin.sewell%40southwales.ac.uk%7C696a3021f54a4aa6c50d08db314383f5%7Ce5aafe7c971b4ab7b039141ad36acec0%7C0%7C0%7C638157938272059800%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=r66i5GfLZsBQp6Y4hO8UJN2W2aZ0Aym9GTV8cc%2BqR%2BI%3D&reserved=0> - Contributions: https://goo.gl/mh7qDG<https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgoo.gl%2Fmh7qDG&data=05%7C01%7Ckevin.sewell%40southwales.ac.uk%7C696a3021f54a4aa6c50d08db314383f5%7Ce5aafe7c971b4ab7b039141ad36acec0%7C0%7C0%7C638157938272059800%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=TvgJZU5Hm%2F6i4ppSY3BZ6J0O7cBte7yuYaw9uKlos%2FA%3D&reserved=0> --- You received this message because you are subscribed to the Google Groups "CAS Community" group. To unsubscribe from this group and stop receiving emails from it, send an email to cas-user+unsubscr...@apereo.org<mailto:cas-user+unsubscr...@apereo.org>. To view this discussion on the web visit https://groups.google.com/a/apereo.org/d/msgid/cas-user/58becabda6781c976c11348b3a3d22d5b22532a8.camel%40uvic.ca<https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgroups.google.com%2Fa%2Fapereo.org%2Fd%2Fmsgid%2Fcas-user%2F58becabda6781c976c11348b3a3d22d5b22532a8.camel%2540uvic.ca%3Futm_medium%3Demail%26utm_source%3Dfooter&data=05%7C01%7Ckevin.sewell%40southwales.ac.uk%7C696a3021f54a4aa6c50d08db314383f5%7Ce5aafe7c971b4ab7b039141ad36acec0%7C0%7C0%7C638157938272059800%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=Y%2B30Mi%2FFTqz4U6qdjrWKJhaPkfgPxiP4RSupNLZMDN4%3D&reserved=0>. -- - Website: https://apereo.github.io/cas - Gitter Chatroom: https://gitter.im/apereo/cas - List Guidelines: https://goo.gl/1VRrw7 - Contributions: https://goo.gl/mh7qDG --- You received this message because you are subscribed to the Google Groups "CAS Community" group. To unsubscribe from this group and stop receiving emails from it, send an email to cas-user+unsubscr...@apereo.org. To view this discussion on the web visit https://groups.google.com/a/apereo.org/d/msgid/cas-user/LO0P265MB64392B35C651EA0AFF99E4C6AA8F9%40LO0P265MB6439.GBRP265.PROD.OUTLOOK.COM.