Authenticate via Shibboleth and LDAP
Cantor, Scott
cantor.2 at osu.edu
Mon Jun 18 15:47:33 BST 2012
On 6/18/12 10:44 AM, "Chad La Joie" <lajoie at itumi.biz> wrote:
>No, I think the docs are right.
I can change them back, but FWIW, I always used "want" back when I ran
Tomcat.
>If I recall correctly, when you set that option to "want" the
>container still asks for the cert which triggers the browser error.
The browser doesn't use that port though. It does happen that if you
access it with the browser, and use IE, you'll still get the prompt, but
it doesn't matter really.
>If you could get the browser to not send display the error and just
>send the request anyways the container gladly continues on without the
>cert.
Which is basically what you want. If we document "true", then any use of
signing in place of TLS breaks without changing every IdP.
>So, the container does not consider it mandatory, the browser does.
It doesn't consider it mandatory *if* you use "want", which is the
intended behavior?
-- Scott
More information about the users
mailing list