defending shib-idp after commercial cert installed for tomcat6
Cantor, Scott
cantor.2 at osu.edu
Wed Jan 8 14:30:24 EST 2014
On 1/8/14, 1:48 PM, "Gene Matthews" <gmatthew at hitachi-cta.com> wrote:
>
>>Well, you'd certainly better not change the certificate for that port.
>>That will break queries, but that has nothing to do with browsers.
>
>Scott, can you elaborate more on this point please? Tomcat connector is
>for port 8443 and our SPs do redirect back to https://<our sso
>server>:8443/...
As Peter said, that's not proper. Something is wrong in your metadata if
you're doing that.
>There is a self-signed cert that is used in the relying-party.xml file in
>the <security:Credential> section (defaults to the idp.crt as I recall).
>Those are used for two different purposes I thought. That cert hasn't
>changed.
The certificate on 8443 is normally the same one as that. The one on 443
is not.
-- Scott
More information about the users
mailing list