Security settings on LDAP connector

Cantor, Scott cantor.2 at osu.edu
Fri Aug 11 12:12:14 EDT 2017


On 8/11/17, 9:32 AM, "Cantor, Scott" <cantor.2 at osu.edu> wrote:

>> Only what is mentioned in IDP-1196 which is basically to do what we did to the MetadataResolver in V3 (inline the 99% case
>> either with a <Certificate> or with a "trustFile=foo.pem" and use bean references for the rest.
>
> I'll look at it, I used certificateAuthority yesterday but I can change that easily enough.

Actually, correct me, but I think the LDAP case is plugging the certificate(s) directly into ldaptive, right? No TrustEngine?

I have to distinguish the "server's key" case from the "validate with CA" case, so I don't think I should probably copy that specific setting.

-- Scott




More information about the dev mailing list