Top Banner
NIEUWE METADATA EN VERIFICATIESLEUTELS VOOR SURFCONEXT SURFconext Key rollover Joost van Dijk 9 april 2019 - What’s next @ SURFconext?
19

SURFconext Key rollover whats next...Metadata below is only relevant for key rollover or in case you want a custom WAYF for your SP The Public SAML metadata (the entity descriptor)

Aug 21, 2020

Download

Documents

dariahiddleston
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: SURFconext Key rollover whats next...Metadata below is only relevant for key rollover or in case you want a custom WAYF for your SP The Public SAML metadata (the entity descriptor)

NIEUWE METADATA EN VERIFICATIESLEUTELS VOOR SURFCONEXT

SURFconext Key rollover

Joost van Dijk9 april 2019 - What’s next @ SURFconext?

Page 2: SURFconext Key rollover whats next...Metadata below is only relevant for key rollover or in case you want a custom WAYF for your SP The Public SAML metadata (the entity descriptor)

Inhoud

• Wat is een key rollover?

• Wat gaat er veranderen?

• Waarom eigenlijk?

Page 3: SURFconext Key rollover whats next...Metadata below is only relevant for key rollover or in case you want a custom WAYF for your SP The Public SAML metadata (the entity descriptor)
Page 4: SURFconext Key rollover whats next...Metadata below is only relevant for key rollover or in case you want a custom WAYF for your SP The Public SAML metadata (the entity descriptor)

SAML assertion anno 1869

Page 5: SURFconext Key rollover whats next...Metadata below is only relevant for key rollover or in case you want a custom WAYF for your SP The Public SAML metadata (the entity descriptor)

Successaffiliation: employee surName: van Dijk

IdP

SAML assertion anno 2019

Page 6: SURFconext Key rollover whats next...Metadata below is only relevant for key rollover or in case you want a custom WAYF for your SP The Public SAML metadata (the entity descriptor)

IdP SP

sp.example.com

Success✓

sign with private key

verify with public key

Page 7: SURFconext Key rollover whats next...Metadata below is only relevant for key rollover or in case you want a custom WAYF for your SP The Public SAML metadata (the entity descriptor)

SP/IdPIdP SP

engine.surfconext.nlidp.example.edu sp.example.com

Success Success✓ ✓

Login?✓

Login?✓

Page 8: SURFconext Key rollover whats next...Metadata below is only relevant for key rollover or in case you want a custom WAYF for your SP The Public SAML metadata (the entity descriptor)

naam: SURFconext

ID: https://engine.surfconext.nl/authentication/idp/metadata

Location: https://engine.surfconext.nl/authentication/idp/single-sign-on/key:20181213

certificaat:

Metadata

Page 9: SURFconext Key rollover whats next...Metadata below is only relevant for key rollover or in case you want a custom WAYF for your SP The Public SAML metadata (the entity descriptor)

Wat verandert er?

Page 10: SURFconext Key rollover whats next...Metadata below is only relevant for key rollover or in case you want a custom WAYF for your SP The Public SAML metadata (the entity descriptor)

https://engine.surfconext.nl https://metadata.surfconext.nl

Page 11: SURFconext Key rollover whats next...Metadata below is only relevant for key rollover or in case you want a custom WAYF for your SP The Public SAML metadata (the entity descriptor)
Page 12: SURFconext Key rollover whats next...Metadata below is only relevant for key rollover or in case you want a custom WAYF for your SP The Public SAML metadata (the entity descriptor)
Page 13: SURFconext Key rollover whats next...Metadata below is only relevant for key rollover or in case you want a custom WAYF for your SP The Public SAML metadata (the entity descriptor)
Page 14: SURFconext Key rollover whats next...Metadata below is only relevant for key rollover or in case you want a custom WAYF for your SP The Public SAML metadata (the entity descriptor)

Waarom eigenlijk?

Page 15: SURFconext Key rollover whats next...Metadata below is only relevant for key rollover or in case you want a custom WAYF for your SP The Public SAML metadata (the entity descriptor)
Page 16: SURFconext Key rollover whats next...Metadata below is only relevant for key rollover or in case you want a custom WAYF for your SP The Public SAML metadata (the entity descriptor)

Leena Snidate / Codenomicon [CC0]

CVE-2014-0160

Page 17: SURFconext Key rollover whats next...Metadata below is only relevant for key rollover or in case you want a custom WAYF for your SP The Public SAML metadata (the entity descriptor)
Page 18: SURFconext Key rollover whats next...Metadata below is only relevant for key rollover or in case you want a custom WAYF for your SP The Public SAML metadata (the entity descriptor)

Samengevat

• Nieuwe Assertion Signing key • Geldig tot 18 december 2024

• Nieuwe metadata locatie • metadata.surfnet.nl

• Nieuwe Metadata Signing key • opgeslagen in HSM • Ieder uur ververst • Certificaat uitgegeven door offline root

• Deadline voor migratie: 1 Mei 2019 • Documentatie: https://edu.nl/keyrollover

Page 19: SURFconext Key rollover whats next...Metadata below is only relevant for key rollover or in case you want a custom WAYF for your SP The Public SAML metadata (the entity descriptor)

@joostd

[email protected]

https://www.linkedin.com/in/joostd/

[email protected]