Possible problem with key exchange
Muzinich, Mike
MuziniM at losrios.edu
Fri Apr 27 00:07:47 BST 2012
The problem was with the Tomcat 6 configuration. After I cloned the production Tomcat 5 configuration, everything works.
Mike Muzinich
Network Security Administrator
Los Rios Community College District
mike.muzinich at losrios.edu
(916)568-3013
From: <Cantor>, Scott <cantor.2 at osu.edu<mailto:cantor.2 at osu.edu>>
Reply-To: Shib Users <users at shibboleth.net<mailto:users at shibboleth.net>>
Date: Thursday, April 26, 2012 6:50 AM
To: Shib Users <users at shibboleth.net<mailto:users at shibboleth.net>>
Subject: Re: Possible problem with key exchange
On 4/25/12 5:32 PM, "Muzinich, Mike" <MuziniM at losrios.edu<mailto:MuziniM at losrios.edu>> wrote:
I brought over the entire /opt/shibboleth-idp directory structure from a
functional system and thought I had Tomcat and Apache configured
correctly but obviously have something configured incorrectly.
The only place that would matter is the IdP itself, what credential it's
using to sign. There's no TLS involved. But I have no idea what Google
does to evaluate the key. If it does a public key compare, it should work.
If it does more with the cert...
Incidentally, the FQDN in the Shibboleth configuration
is a CNAME which I change to go from our production system to the new
system.
That suggests they are doing more with the cert.
-- Scott
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net<mailto:users-unsubscribe at shibboleth.net>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20120426/3f98f1f8/attachment.html
More information about the users
mailing list