Education & research · Identity Management · Library IT · Research Computing
Rotate federation signing keys across campus and research services
Which relying services will reject a new federation signer, and how quickly can stale metadata be corrected?
Operational pain
Departments and external research services cache metadata differently, turning a key rollover into widespread login failure.
Trigger
Identity-provider migration, scheduled rollover, compromise, or merger of institutions.
QNSI contribution
Connect the decision to a controlled security path
Inventory federation keys, relying parties, metadata refresh, audiences, algorithms, owners, and last verification in QNSI.
Decision artifact
A campus federation rollover matrix with test accounts, metadata lag, escalation owners, and retirement proof.
What still requires validation
The institution tests authentication assurance, accessibility, privacy, emergency login, external partners, and help-desk readiness.
External problem context
Primary sources
These sources establish the external requirement or risk context. They do not endorse HEOSSI or prove that QNSI completed this scenario.
Evidence boundary
What this page does—and does not—prove
This is a product evaluation pattern, not a customer case study, certification, legal opinion, regulator endorsement, or claim that a production deployment completed the described work.