IdP & LDAP source using private CA

David Bantz dabantz at alaska.edu
Mon Apr 15 17:07:05 EDT 2013


On Mon, 15 Apr 2013, at 12:44 , Peter Schober <peter.schober at univie.ac.at> wrote:

> If you need to go through all that trouble to avoid untrustworthy
> certificates of your own making you're Doing It Wrong. 

Neither the certs nor the private CA is of my own making of course;
they are for the convenience of the group providing and administering
the relevant Domain Controllers; the private CA using MS tools makes
their internal operations much easier and more robust - so they say.

> Put that custom CA into your JVM truststore, done.
 
Well...done until an update or patch replaces the JVM keystore with
a newer version of trusted CAs, yes?

David Bantz
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130415/c41965b1/attachment.html 


More information about the users mailing list