CURLSOAPTransport failure for SP 2.5.2 on CentOS 5.x

Takeshi NISHIMURA takeshi at nii.ac.jp
Wed Nov 6 23:30:15 EST 2013


(2013/11/07 0:28), Cantor, Scott wrote:
> so it would just create interop problems for people.
> It's easier to just follow standard https rules as much as possible.)

We had similar problem in this field.
SP's certificate should have clientAuth(*) flag in extendedKeyUsage (eKU) if you have any eKU in it. Otherwise you will have interop problem on SOAP with some non-Shibboleth IdPs.

Is there any plan to enable additional checks like this?

(*) - oid:1.3.6.1.5.5.7.3.2

Best regards,
Takeshi


More information about the users mailing list