defending shib-idp after commercial cert installed for tomcat6
Gene Matthews
gmatthew at hitachi-cta.com
Wed Jan 8 13:48:48 EST 2014
>Well, you'd certainly better not change the certificate for that port.
>That will break queries, but that has nothing to do with browsers.
Scott, can you elaborate more on this point please? Tomcat connector is for port 8443 and our SPs do redirect back to https://<our sso server>:8443/...
There is a self-signed cert that is used in the relying-party.xml file in the <security:Credential> section (defaults to the idp.crt as I recall). Those are used for two different purposes I thought. That cert hasn't changed.
Thanks,
Gene
More information about the users
mailing list