certificate name was not acceptable

Pete Scott PScott at t2systems.com
Thu Jun 13 16:02:03 EDT 2013


> > If you're not trying to pass attributes over the back channel, either
> > take the Attribute Authority endpoints out of the IdP metadata or
> > remove this line from shibboleth2.xml:
> >
> >         <!-- Use a SAML query if no attributes are supplied during SSO. -->
> >         <AttributeResolver type="Query" subjectMatch="true"/>
> 
> But do NOT do that if you're using queries with other SAML 1.1 IdPs. (Hint:
> you are, mine ;-)
> 
Hmmm... can that be modified inside of an ApplicationOverride?

> In this case it's not in question why. The certificate name isn't right or the
> hostname of the endpoint in the metadata for queries isn't.
> 
Thanks! Any thoughts on what might be the very best way to PROVE that to the client?


More information about the users mailing list