CURLSOAPTransport failure for SP 2.5.2 on CentOS 5.x

Cantor, Scott cantor.2 at osu.edu
Thu Nov 7 10:47:15 EST 2013


On 11/6/13, 11:30 PM, "Takeshi NISHIMURA" <takeshi at nii.ac.jp> wrote:
>
>We had similar problem in this field.
>SP's certificate should have clientAuth(*) flag in extendedKeyUsage (eKU)
>if you have any eKU in it. Otherwise you will have interop problem on
>SOAP with some non-Shibboleth IdPs.

We don't put any eKU in the certificate as far as I'm aware. We're aware
that using them creates problems that leaving them out does not.

>Is there any plan to enable additional checks like this?

I'm not sure I understand what you're referring to or in what component.

-- Scott




More information about the users mailing list