You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: README.md
+7Lines changed: 7 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -453,6 +453,12 @@ The Service Provider will decrypt the EncryptedAssertion with its private key.
453
453
454
454
Notice that this toolkit uses 'settings.certificate' and 'settings.private_key' for the sign and decrypt processes.
455
455
456
+
457
+
## Key rollover
458
+
459
+
If you plan to update the SP x509cert and privateKey you can define the parameter 'certificate_new' at the settings and that new SP public certificate will be published on the SP metadata so Identity Providers can read them and get ready for rollover.
460
+
461
+
456
462
## Single Log Out
457
463
458
464
The Ruby Toolkit supports SP-initiated Single Logout and IdP-Initiated Single Logout.
@@ -583,6 +589,7 @@ class SamlController < ApplicationController
583
589
end
584
590
```
585
591
592
+
586
593
## Clock Drift
587
594
588
595
Server clocks tend to drift naturally. If during validation of the response you get the error "Current time is earlier than NotBefore condition", this may be due to clock differences between your system and that of the Identity Provider.
0 commit comments