LDAP SSL with it's own JKS on IDP?

Byte Flinger byteflinger at gmail.com
Tue Oct 15 08:42:56 EDT 2013


Hi

I have read the Shibboleth IDP wiki page on how to configure ldap ssl using
java's own keystore and my tests worked fine that way using ldaps however I
would like to use my own separate keystore somewhere else in the disk.

I tried using the "sslSocketFactory" on login.config to point to a JKS but
that gives me some IO errors, also pointing to just the crt of the CA did
not seem to work (Got certificate path errors even though I tried both with
the client certificate and the CA certificate immediately under it).

Is it possible to use a separate keystore for both login and also for the
attribute connector?

I should mention that this is on IDP 2.4 and that I am not using StartTLS,
it is a straight ssl connection to the ldap server.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20131015/3eed94d6/attachment.html 


More information about the users mailing list