SSL offloading breaks ECP

Cantor, Scott cantor.2 at osu.edu
Tue Jan 29 14:09:34 EST 2013


On 1/29/13 1:15 PM, "Ryan Suarez" <ryan.suarez at sheridancollege.ca> wrote:
>
>tcpdumps on the IdP shows it redirecting the SP to port 8443.  basic
>auth was configured with a transport-guarantee of 'CONFIDENTIAL' which
>was forcing this redirect.  If I set transport-guarantee to 'NONE' then
>ECP works.
>
>Any concerns with leaving transport-guarantee as 'NONE'?

That would depend on your environment, I guess. Obviously if it's not SSL
end to end, the passwords are in the clear somewhere.

-- Scott




More information about the users mailing list