Security settings on LDAP connector

Cantor, Scott cantor.2 at osu.edu
Fri Aug 11 09:32:42 EDT 2017


On 8/11/17, 4:04 AM, "dev on behalf of Rod Widdowson" <dev-bounces at shibboleth.net on behalf of rdw at steadingsoftware.com> wrote:

> Only what is mentioned in IDP-1196 which is basically to do what we did to the MetadataResolver in V3 (inline the 99% case
> either with a <Certificate> or with a "trustFile=foo.pem" and use bean references for the rest.

I'll look at it, I used certificateAuthority yesterday but I can change that easily enough.

I have to handle some additional cases. I know we're deprecating some of the options like username/password on the metadata, but I think that's probably reasonable given that it's pretty much never used there. Whereas it's pretty clearly needed as a shortcut for a web service connector.

-- Scott





More information about the dev mailing list