Login.config vs. attribute-resolve.xml?

Nate Klingenstein ndk at internet2.edu
Mon Jun 4 19:36:25 BST 2012


Andy,

The connection overhead is the primary objection to the use of LDAPS.   
If the IdP and the directory are communicating over a truly private/ 
protected network, then adding LDAPS on top of that is extra overhead  
for limited benefit.

In all other situations(e.g. most of them), I think the use of LDAPS/ 
STARTTLS is advisable.

Congrats on the interop with TestShib,
Nate.

On Jun 4, 2012, at 18:22 , Kanuch, Andy wrote:

> Is there any reason to not use LDAPS over LDAP as the connection  
> protocol?

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20120604/d091a83e/attachment.html 


More information about the users mailing list