Certificate practices using IdP with MS AD LDAP

Glenn Wearen glenn.wearen at heanet.ie
Tue Jun 25 09:32:59 EDT 2013


I hit this issue a few weeks ago, I tried switching off SSL hostname checks but ended up having to switch to plain ldap as  the IdP (or the vt ldap library) assumed that the cert offered on AD server 1 should also be trusted on AD server 2 and rejects the cert offered by AD server 2.
I should have logged a bug but didn't.
Glenn

Edugate Operations
HEAnet Limited, Ireland's Education and Research Network - 
1st Floor, 5 George's Dock, IFSC, Dublin 1
Registered in Ireland, no 275301  tel: +353-1-6609040  fax: +353-1-6603666

On 25 Jun 2013, at 00:01, David Bantz wrote:

> 
> On Wed, 24 Apr 2013, at 10:45 , Daniel Fisher <dfisher at vt.edu> wrote:
> 
>> If you're using LDAP for authentication you would configure the JAAS module as well:
>> sslSocketFactory="{trustCertificates=file:/path/to/my/trust.crt}"
> 
> Using failover redundancy like
> 
> edu.vt.middleware.ldap.jaas.LdapLoginModule sufficient 
> ldapUrl="ldap://adua01.ua.ad.alaska.edu:3269 ldap://adua02.ua.ad.alaska.edu:3269"
>> 
> can I - if so how would I - indicate different certificates for each server?
> 
> David Bantz
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130625/b5ad36b8/attachment-0001.html 
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 2330 bytes
Desc: not available
Url : http://shibboleth.net/pipermail/users/attachments/20130625/b5ad36b8/attachment-0001.bin 


More information about the users mailing list