defending shib-idp after commercial cert installed for tomcat6

Cantor, Scott cantor.2 at osu.edu
Wed Jan 8 12:01:24 EST 2014


On 1/8/14, 11:57 AM, "Gene Matthews" <gmatthew at hitachi-cta.com> wrote:
>
>We have a working shibboleth-idp (2.4.0) running under tomcat 6.0.24 on
>CentOS 6.5.  Tomcat had a self-signed cert (currently still does as we
>had to revert back to it).  A commercial SSL cert was received and put in
>place on tomcat (with appropriate edits in the server.xml file) by
>someone other than me.  With the commercial cert in place, tomcat starts
>ok with no error messages and indicates the idp starts up with no error
>messages.  Tomcat connector (port 8443) also starts up and a netstat
>shows something
> listening on that port.

Well, you'd certainly better not change the certificate for that port.
That will break queries, but that has nothing to do with browsers.

>However, with commercial cert in place we can't get to our SSO login page
>from the redirect at the SP.  Browsers give some less than useful generic
>SSL error.

The IdP has nothing to do with actually doing the TLS negotiation with any
client.

-- Scott




More information about the users mailing list