Shibboleth 2.5.1 blacklist of RSA 1.5

Cantor, Scott cantor.2 at osu.edu
Tue Jan 29 11:45:29 EST 2013


> I also dug further into the code, and see this..

I'm coming into the middle of this conversation, if this is in reference to some earlier thread I don't know what it is or what you're asking about.

> So if includeDefaultBlacklist is supposed to pick the "false" from my
> security-policy.xml, but it doesn't, where is this
> shibboleth-2.0-native-sp-config.xsd called from?  Why is it not using the
> "false" attribute passed back to it?  I have verified that the
> /var/run/shibboleth/security-policy.xml also has "false" for
> includeDefaultBlacklist

If you're trying to disable the internal blacklist, then setting that flag to false in security-policy.xml is how you do that. The schema has nothing to do with it.

I added a fair bit of logging to make sure it logs what's getting blacklisted so that it's traceable.

-- Scott




More information about the users mailing list