SURFconext Key rollover whats next...Metadata below is only relevant for key rollover or in case you...

19
NIEUWE METADATA EN VERIFICATIESLEUTELS VOOR SURFCONEXT SURFconext Key rollover Joost van Dijk 9 april 2019 - What’s next @ SURFconext?

Transcript of SURFconext Key rollover whats next...Metadata below is only relevant for key rollover or in case you...

Page 1: SURFconext Key rollover whats next...Metadata below is only relevant for key rollover or in case you want a custom WAYF for your SP The Public SAML metadata (the entity descriptor)

NIEUWE METADATA EN VERIFICATIESLEUTELS VOOR SURFCONEXT

SURFconext Key rollover

Joost van Dijk9 april 2019 - What’s next @ SURFconext?

Page 2: SURFconext Key rollover whats next...Metadata below is only relevant for key rollover or in case you want a custom WAYF for your SP The Public SAML metadata (the entity descriptor)

Inhoud

• Wat is een key rollover?

• Wat gaat er veranderen?

• Waarom eigenlijk?

Page 3: SURFconext Key rollover whats next...Metadata below is only relevant for key rollover or in case you want a custom WAYF for your SP The Public SAML metadata (the entity descriptor)
Page 4: SURFconext Key rollover whats next...Metadata below is only relevant for key rollover or in case you want a custom WAYF for your SP The Public SAML metadata (the entity descriptor)

SAML assertion anno 1869

Page 5: SURFconext Key rollover whats next...Metadata below is only relevant for key rollover or in case you want a custom WAYF for your SP The Public SAML metadata (the entity descriptor)

Successaffiliation: employee surName: van Dijk

IdP

SAML assertion anno 2019

Page 6: SURFconext Key rollover whats next...Metadata below is only relevant for key rollover or in case you want a custom WAYF for your SP The Public SAML metadata (the entity descriptor)

IdP SP

sp.example.com

Success✓

sign with private key

verify with public key

Page 7: SURFconext Key rollover whats next...Metadata below is only relevant for key rollover or in case you want a custom WAYF for your SP The Public SAML metadata (the entity descriptor)

SP/IdPIdP SP

engine.surfconext.nlidp.example.edu sp.example.com

Success Success✓ ✓

Login?✓

Login?✓

Page 8: SURFconext Key rollover whats next...Metadata below is only relevant for key rollover or in case you want a custom WAYF for your SP The Public SAML metadata (the entity descriptor)

naam: SURFconext

ID: https://engine.surfconext.nl/authentication/idp/metadata

Location: https://engine.surfconext.nl/authentication/idp/single-sign-on/key:20181213

certificaat:

Metadata

Page 9: SURFconext Key rollover whats next...Metadata below is only relevant for key rollover or in case you want a custom WAYF for your SP The Public SAML metadata (the entity descriptor)

Wat verandert er?

Page 10: SURFconext Key rollover whats next...Metadata below is only relevant for key rollover or in case you want a custom WAYF for your SP The Public SAML metadata (the entity descriptor)

https://engine.surfconext.nl https://metadata.surfconext.nl

Page 11: SURFconext Key rollover whats next...Metadata below is only relevant for key rollover or in case you want a custom WAYF for your SP The Public SAML metadata (the entity descriptor)
Page 12: SURFconext Key rollover whats next...Metadata below is only relevant for key rollover or in case you want a custom WAYF for your SP The Public SAML metadata (the entity descriptor)
Page 13: SURFconext Key rollover whats next...Metadata below is only relevant for key rollover or in case you want a custom WAYF for your SP The Public SAML metadata (the entity descriptor)
Page 14: SURFconext Key rollover whats next...Metadata below is only relevant for key rollover or in case you want a custom WAYF for your SP The Public SAML metadata (the entity descriptor)

Waarom eigenlijk?

Page 15: SURFconext Key rollover whats next...Metadata below is only relevant for key rollover or in case you want a custom WAYF for your SP The Public SAML metadata (the entity descriptor)
Page 16: SURFconext Key rollover whats next...Metadata below is only relevant for key rollover or in case you want a custom WAYF for your SP The Public SAML metadata (the entity descriptor)

Leena Snidate / Codenomicon [CC0]

CVE-2014-0160

Page 17: SURFconext Key rollover whats next...Metadata below is only relevant for key rollover or in case you want a custom WAYF for your SP The Public SAML metadata (the entity descriptor)
Page 18: SURFconext Key rollover whats next...Metadata below is only relevant for key rollover or in case you want a custom WAYF for your SP The Public SAML metadata (the entity descriptor)

Samengevat

• Nieuwe Assertion Signing key • Geldig tot 18 december 2024

• Nieuwe metadata locatie • metadata.surfnet.nl

• Nieuwe Metadata Signing key • opgeslagen in HSM • Ieder uur ververst • Certificaat uitgegeven door offline root

• Deadline voor migratie: 1 Mei 2019 • Documentatie: https://edu.nl/keyrollover

Page 19: SURFconext Key rollover whats next...Metadata below is only relevant for key rollover or in case you want a custom WAYF for your SP The Public SAML metadata (the entity descriptor)

@joostd

[email protected]

https://www.linkedin.com/in/joostd/

[email protected]