LDAP SSL with it's own JKS on IDP?
Byte Flinger
byteflinger at gmail.com
Tue Oct 15 08:42:56 EDT 2013
Hi
I have read the Shibboleth IDP wiki page on how to configure ldap ssl using
java's own keystore and my tests worked fine that way using ldaps however I
would like to use my own separate keystore somewhere else in the disk.
I tried using the "sslSocketFactory" on login.config to point to a JKS but
that gives me some IO errors, also pointing to just the crt of the CA did
not seem to work (Got certificate path errors even though I tried both with
the client certificate and the CA certificate immediately under it).
Is it possible to use a separate keystore for both login and also for the
attribute connector?
I should mention that this is on IDP 2.4 and that I am not using StartTLS,
it is a straight ssl connection to the ldap server.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20131015/3eed94d6/attachment.html
More information about the users
mailing list