Authenticate via Shibboleth and LDAP
Stephan Hackstedt
stephan.hackstedt at googlemail.com
Mon Jun 18 11:34:47 BST 2012
Hi,
the problem was, that when enabled clientAuth, the Client (Browser) needs a
PKAS Certificate.
So I created one from the idp.jks file with openssl, added it to firefox
certificates and now it works.
I'm wondering why SSLCertificateFile and SSLCertificateKeyFile don't have a
effect on the redirecting procedure.
I can use a self created one or even sp-cert.pem and sp-key.pem from the
service provider.
Stephan
2012/6/17 Chad La Joie <lajoie at itumi.biz>
> I don't know what to tell you. The connector configuration you gave
> is listening on port 8433, the URL you are showing is not hitting that
> port so you either have something between the browser and the server
> changing the port that is being accessed or the URL or the config you
> gave is not what you're using.
>
> On Sun, Jun 17, 2012 at 1:04 PM, Stephan Hackstedt
> <stephan.hackstedt at googlemail.com> wrote:
> > I could solve a part of the problem, and know I can access the
> >
> > https://sp.machine.com:553/Shibboleth.sso/Metadata (SP runs under port
> 553,
> > cause both SP and IdP are running on the same machine)
> > and
> > https://idp.machine.com/idp/profile/Status
> >
> > Nevertheless, when setting clientAuth="true" in tomcats server.xml I
> always
> > got the follwing error when trying to access a protecetd ressource.
> >
> > ssl_error_bad_cert_alert
>
> --
> Chad La Joie
> www.itumi.biz
> trusted identities, delivered
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20120618/dd4e050e/attachment.html
More information about the users
mailing list