Issue with upgrading to 2.3.6
Peter Schober
peter.schober at univie.ac.at
Wed Feb 29 16:36:41 GMT 2012
* Halm Reusser <halm.reusser at switch.ch> [2012-02-29 16:26]:
> But people with issues have now the choice between stick on 2.3.5 or buy
> a new cert - assumed they do not like to implement a custom
> HostnameVerifier, right?
Or use RFC-blessed methods like StartTLS in the first place.
Or don't use TLS/SSL at all and rely on DNS and network security
between the IdP and the directory service.
Or use Kerberos instead of LDAP for authentication (but then the
problem remains for LDAP-based data connectors).
Or use stunnel etc. to create a secure connection to the directory
service and connect the IDP to the tunnel.
I'm sure there are more choices still.
-peter
More information about the users
mailing list