defending shib-idp after commercial cert installed for tomcat6

Peter Schober peter.schober at univie.ac.at
Wed Jan 8 14:04:13 EST 2014


* Gene Matthews <gmatthew at hitachi-cta.com> [2014-01-08 19:49]:
> Scott, can you elaborate more on this point please?  Tomcat
> connector is for port 8443 and our SPs do redirect back to
> https://<our sso server>:8443/...

Unless you're saying that your normal webserver port intended for
users' web browsers is 8443 this is wrong. That port is not intended
for end users or SSO. If an SP sends your browser there your metadata
is probaly wrong (assuming the SP consumed your metadata somehow).
-peter


More information about the users mailing list