IdP & LDAP source using private CA

Cantor, Scott cantor.2 at osu.edu
Mon Apr 15 15:49:03 EDT 2013


On 4/15/13 3:19 PM, "David Bantz" <dabantz at alaska.edu> wrote:

>But failover does not appear to cover the case of connection failure due
>to untrusted certificate:
>the attribute-resolver aborts encountering an untrusted certificate; in
>fact the IdP startup process
>itself aborts encountering untrusted certificate in the DataConnector.

Those are two separate issues. The resolver doesn't handle that any
differently than any other failure as far as I know. But if you want
non-fail fast at start up, you'll have to set options (for JDBC) or wait
for 2.4 (for LDAP), or plugin some custom code I use for getting the LDAP
pools to stop aborting at start time.

But I will say that people screwing with certificates was not a primary
use case for the fail fast option. The IdP software cannot make a
dysfunctional IT department functional. I say this with long experience.

-- Scott




More information about the users mailing list