QNSI

Education & research · Identity Management · Library IT · Research Computing

Rotate federation signing keys across campus and research services

Which relying services will reject a new federation signer, and how quickly can stale metadata be corrected?

Operational pain

Departments and external research services cache metadata differently, turning a key rollover into widespread login failure.

Trigger

Identity-provider migration, scheduled rollover, compromise, or merger of institutions.

QNSI contribution

Connect the decision to a controlled security path

Inventory federation keys, relying parties, metadata refresh, audiences, algorithms, owners, and last verification in QNSI.

Decision artifact

A campus federation rollover matrix with test accounts, metadata lag, escalation owners, and retirement proof.

What still requires validation

The institution tests authentication assurance, accessibility, privacy, emergency login, external partners, and help-desk readiness.

External problem context

Primary sources

These sources establish the external requirement or risk context. They do not endorse HEOSSI or prove that QNSI completed this scenario.

Evidence boundary

What this page does—and does not—prove

This is a product evaluation pattern, not a customer case study, certification, legal opinion, regulator endorsement, or claim that a production deployment completed the described work.